CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

IBM security advisory (AV26-789)

unknown
Serial Number: AV26-789 Date: August 10, 2026 As of August 7, 2026, IBM is affected by vulnerabilities in the following products: Application Gateway Operator Prior to or equal to 26.06 Big SQL on IBM Cloud Pak for Data Version Big SQL 7.7 on Cloud Pak for Data 5.0 Big SQL on IBM Software Hub Multiple versions Business Automation Workflow containers and traditional 26.0.0 Prior to or equal to 24.0.0 Interim Fix 009 Prior to or equal to 24.0.1 Interim Fix 007 Prior to or equal to 25.0.0 Interim Fix 005 Cloud APM, Advanced/Base Private Prior to or equal to 8.1.4 Cloud Pak For Business Automation 24.0.0 24.0.1 25.0.0 26.0.0 IBM Event Streams version 13.0.1 Langflow OSS Prior to or equal to 1.10.3 Maximo Application Suite 9.0 9.1 9.2 IBM Netezza Appliance 1.0.2.0 Operational Decision Manager Multiple versions PowerVC Multiple versions Process Automation Manager Open Edition Starter Kit for Banking Prior to or equal to 9.4.1 SevOne Network Performance Management (Data Insight) Prior to or equal to 8.2.2 QRadar Prior to or equal to 7.5.0 UP 15 Interim Fix 005 Prior to or equal to 7.6.0.1 Security Verify Information Queue Multiple versions Storage Protect Operations Center Versions prior or equal to 8.1 and 8.2 webMethods Managed File Transfer (on-prem) Prior to or equal to 11.1 and 12.1 WebSphere Application Server 8.5 9.0 WebSphere Application Server - Liberty Continuous delivery The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. IBM Product Security Incident Response

CSIRTS triage

What
IBM has published a security advisory covering multiple products including Application Gateway Operator, Big SQL, Business Automation Workflow, Cloud APM, Cloud Pak for Business Automation, Event Streams, Langflow OSS, Maximo Application Suite, Netezza Appliance, Operational Decision Manager, PowerVC, and Process Automation Manager.
Who is affected
Organizations deploying any of the affected IBM products listed in advisory AV26-789 at the specified versions.
Urgency
Severity unknown; no exploitation status, CVE details, or specific vulnerability descriptions provided, limiting immediate risk assessment.
Action
Review IBM's detailed security advisory AV26-789 and apply vendor-recommended updates to each affected product.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-10
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-789

More from Canadian Centre for Cyber Security