Multiple vulnerabilities in IBM products (August 21, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM products allow remote arbitrary code execution, privilege escalation, and denial of service.
- Who is affected
- IBM product deployments across multiple product lines.
- Urgency
- Critical: exploitation is already occurring in the wild.
- Action
- Review IBM security advisories for affected products, identify which are deployed, and apply patches immediately for any actively exploited CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1067/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-168570.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-599960.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169230.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-599950.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-168440.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-168180.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506450.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-171450.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] IBM WebSphere Application Server: Multiple vulnerabilities enable Denial of Servicecert-bund
- high[NEW] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Java SE: Multiple vulnerabilitiescert-bund
- high[NEW] [high] IBM License Metric Tool: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0321 [1.00] [M/H] Multiple vulnerabilities fixed in IBM AIX and IBM PowerVM VIOSncsc-nl
- high[NEW] [high] IBM AIX and VIOS: Multiple vulnerabilitiescert-bund
- highCVE-2026-19446: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can sen…nvd
- highCVE-2026-19437: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitra…nvd
- criticalCVE-2026-18835: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to e…nvd
- criticalCVE-2026-17160: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitra…nvd
- criticalCVE-2026-17145: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitra…nvd
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis · 2026-08-14
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-08-13
- highCVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unve…nvd · 2026-08-12
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis · 2026-08-07
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-30
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21