Multiple vulnerabilities in IBM products (August 07, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities across IBM products allow remote code execution, privilege escalation, and denial of service.
- Who is affected
- IBM product customers across multiple product lines are affected.
- Urgency
- High urgency; RCE and privilege escalation vectors present significant risk.
- Action
- Check IBM security advisories for specific product affected versions and apply patches accordingly.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0986/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506450.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-458520.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-435151.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-316850.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-161840.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-153280.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-424960.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Apache HttpComponents Core: Multiple vulnerabilities allow Denial of Servicecert-bund
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] cPanel cPanel/WHM (Archive-Tar): Multiple vulnerabilities enable file manipulationcert-bund
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 07, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 07, 2026)cert-fr-avis
- high[UPDATE] [high] Unbound: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache Tomcat: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] dnsmasq: Multiple vulnerabilitiescert-bund
- low[UPDATE] [low] expat: Vulnerability allows Denial of Servicecert-bund
- high[UPDATE] [high] Xen and Citrix Systems XenServer: Multiple vulnerabilitiescert-bund
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-30
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis · 2026-07-24
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-23
- unknownIBM WebSphere Products Security Restriction Bypass Vulnerabilityhkcert · 2026-07-17
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis · 2026-07-17
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Progress Telerik (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Google Chrome (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Debian Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Debian LTS Linux kernel (August 07, 2026)2026-08-07