IBM security advisory (AV26-770)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-770 Date: August 4, 2026 As of July 30, 2026, IBM is affected by vulnerabilities in the following products: App Connect Enterprise Prior to or equal to 12.0.12.27 Prior to or equal to 13.0.7.2 DataPower Gateway 10.5.0 Prior to or equal to 10.5.0.21 DataPower Gateway 10.6.0 Prior to or equal to 10.6.0.9 DataPower Gateway 10.6CD Prior to or equal to 10.6.6 DataPower Gateway 11.0.0 Prior to or equal to 11.0.0.1 Db2 Prior to or equal to 11.5.9 Prior to or equal to 12.1.4 Engineering Requirements Management DOORS and DOORS Web Access Prior to or equal to 9.6.1.13 Prior to or equal to 9.7.2.11 Enterprise Build of Quarkus Prior to or equal to 3.27.4.SP2 Prior to or equal to 3.33.2.SP2 HMC V10.3.1050.0 Prior to or equal to 10.3.1064.0 HMC V11.1.1110.0 Prior to or equal to 11.1.1112.0 Langflow OSS Prior to or equal to 1.10.0 Prior to or equal to 1.10.1 Prior to or equal to 1.8.4 Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3 1.3.6.0, 1.3.6.1 1.3.7.0, 1.3.7.1, 1.3.7.2 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 Planning Analytics Local Prior to or equal to 2.1.21 PowerVM Hypervisor Prior to or equal to FW1060.71 Prior to or equal to FW1110.20 Prior to or equal to FW950.H1 Security Verify Access Prior to or equal to 10.0.9.1 Security Verify Access Container Prior to or equal to 10.0.9.1 UCD - IBM DevOps Deploy Prior to or equal to 8.0.1.13 Prior to or equal to 8.1.2.6 Prior to or equal to 8.2.1.0 UCD - IBM UrbanCode Deploy Prior to or equal to 7.2.3.23 Prior to or equal to 7.3.2.18 Verify Identity Access Prior to or equal to 11.0.2 Verify Identity Access Container Prior to or equal to 11.0.2 WebSphere Application Server 8.5 9.0 WebSphere Application Server - Liberty Prior to or equal to 26.0.0.7 webMethods Integration (on prem) 10.15, 10.11 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. On August 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) add
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-770
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-9198Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 77% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9198 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [high] IBM Langflow Desktop OSS: Multiple vulnerabilitiescert-bund
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-9198: IBM Langflow Code Injection Vulnerabilitycisa-kev
- unknownNCSC-2026-0251 [1.00] [M/H] Vulnerabilities fixed in IBM Langflow OSSncsc-nl
- criticalCVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_lo…nvd
More from Canadian Centre for Cyber Security
- unknownVeeam security advisory (AV26-777)2026-08-04
- unknownAdobe security advisory (AV26-776)2026-08-04
- unknownN-able security advisory (AV26-769) - Update 12026-08-04
- unknownMISP security advisory (AV26-775)2026-08-04
- unknownCheckpoint security advisory (AV26-774)2026-08-04