Multiple vulnerabilities in IBM products (August 14, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM products allow remote arbitrary code execution, privilege escalation, and remote denial of service.
- Who is affected
- Multiple IBM product deployments are affected across unspecified versions.
- Urgency
- High; exploitation is actively occurring and includes remote code execution.
- Action
- Identify affected IBM products from the CVE list and apply vendor patches for CVE-2026-5588, CVE-2026-33871, and related CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1032/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-444050.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-329900.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506450.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-454160.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505600.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-666140.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-339400.70% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Oracle Java SE: Multiple vulnerabilitiescert-bund
- highexploited[UPDATE] [high] http/2 implementations: Vulnerability allows denial of servicecert-bund
- high[NEW] [high] IBM WebSphere Application Server Liberty: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Red Hat Enterprise Linux (python-idna): Vulnerability Enables Denial of Servicecert-bund
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilitiescert-bund
- medium[NEW] [medium] IBM WebSphere Application Server: Multiple vulnerabilities enable Denial of Servicecert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM WebSphere Application Server: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Apache CXF: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Netty: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Netty: Multiple vulnerabilitiescert-bund
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-08-13
- highCVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unve…nvd · 2026-08-12
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis · 2026-08-07
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-30
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis · 2026-07-24
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14