IBM security advisory (AV26-789)
Serial Number: AV26-789 Date: August 10, 2026 As of August 7, 2026, IBM is affected by vulnerabilities in the following products: Application Gateway Operator Prior to or equal to 26.06 Big SQL on IBM Cloud Pak for Data Version Big SQL 7.7 on Cloud Pak for Data 5.0 Big SQL on IBM Software Hub Multiple versions Business Automation Workflow containers and traditional 26.0.0 Prior to or equal to 24.0.0 Interim Fix 009 Prior to or equal to 24.0.1 Interim Fix 007 Prior to or equal to 25.0.0 Interim Fix 005 Cloud APM, Advanced/Base Private Prior to or equal to 8.1.4 Cloud Pak For Business Automation 24.0.0 24.0.1 25.0.0 26.0.0 IBM Event Streams version 13.0.1 Langflow OSS Prior to or equal to 1.10.3 Maximo Application Suite 9.0 9.1 9.2 IBM Netezza Appliance 1.0.2.0 Operational Decision Manager Multiple versions PowerVC Multiple versions Process Automation Manager Open Edition Starter Kit for Banking Prior to or equal to 9.4.1 SevOne Network Performance Management (Data Insight) Prior to or equal to 8.2.2 QRadar Prior to or equal to 7.5.0 UP 15 Interim Fix 005 Prior to or equal to 7.6.0.1 Security Verify Information Queue Multiple versions Storage Protect Operations Center Versions prior or equal to 8.1 and 8.2 webMethods Managed File Transfer (on-prem) Prior to or equal to 11.1 and 12.1 WebSphere Application Server 8.5 9.0 WebSphere Application Server - Liberty Continuous delivery The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. IBM Product Security Incident Response
CSIRTS triage
- What
- IBM has published a security advisory covering multiple products including Application Gateway Operator, Big SQL, Business Automation Workflow, Cloud APM, Cloud Pak for Business Automation, Event Streams, Langflow OSS, Maximo Application Suite, Netezza Appliance, Operational Decision Manager, PowerVC, and Process Automation Manager.
- Who is affected
- Organizations deploying any of the affected IBM products listed in advisory AV26-789 at the specified versions.
- Urgency
- Severity unknown; no exploitation status, CVE details, or specific vulnerability descriptions provided, limiting immediate risk assessment.
- Action
- Review IBM's detailed security advisory AV26-789 and apply vendor-recommended updates to each affected product.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-789
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24