Multiple vulnerabilities in IBM products (July 10, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote denial of service, data confidentiality breaches, and server-side request forgery (SSRF).
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote denial of service, data confidentiality breaches, and server-side request forgery (SSRF).
- Who is affected
- Deployments of affected IBM products are affected.
- Urgency
- Remediation is urgent due to the potential for serious security issues including denial of service and data breaches.
- Action
- Update to the latest versions of affected IBM products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0865/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-260070.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-506450.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-113830.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-398920.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-91710.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115410.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-117070.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115460.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-340730.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-115940.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] IBM WebSphere Application Server: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] IBM WebSphere Application Server: Multiple vulnerabilities enable Denial of Servicecert-bund
- medium[UPDATE] [medium] Red Hat Hardened Images RPMs: Multiple vulnerabilitiescert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- high[NEW] [high] Splunk SOAR: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Splunk products (20 August 2026)cert-fr-avis
- unknownNCSC-2026-0307 [1.00] [M/H] Vulnerabilities resolved in Oracle Database Productsncsc-nl
- medium[UPDATE] [medium] Apache CXF: Multiple vulnerabilitiescert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- high[UPDATE] [high] Red Hat Enterprise Linux (urllib3): Multiple vulnerabilities allow denial of servicecert-bund
- medium[NEW] [medium] IBM WebSphere Application Server Liberty: Vulnerability allows denial of servicecert-bund
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21