Multiple vulnerabilities in IBM products (July 31, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM products including remote code execution, privilege escalation, and denial of service flaws.
- Who is affected
- Multiple IBM product lines are affected; specific products and versions not detailed in advisory.
- Urgency
- High; RCE vulnerabilities warrant immediate remediation across affected IBM products.
- Action
- Identify affected IBM products in your environment and apply relevant patches from IBM security updates.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0958/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-455050.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-661990.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-34490.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598710.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-425880.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-338450.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-440250.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-422531.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-398300.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri,…cert-bund
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- medium[UPDATE] [medium] Golang Go-Module (Net, Image, Crypto): Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabiliti…cert-bund
- high[UPDATE] [high] IBM App Connect Enterprise: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Ruby: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] HCL BigFix Compliance (Ruby): Multiple vulnerabilitiescert-bund
- highexploited[UPDATE] [medium] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund
- high[NEW] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- medium[UPDATE] [medium] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Bouncy Castle BC-JAVA: Multiple vulnerabilitiescert-bund
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-30
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis · 2026-07-24
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-23
- unknownIBM WebSphere Products Security Restriction Bypass Vulnerabilityhkcert · 2026-07-17
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis · 2026-07-17
- unknownMultiple vulnerabilities in IBM products (July 10, 2026)cert-fr-avis · 2026-07-10
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06