Multiple vulnerabilities in IBM products (August 28, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities were discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities across IBM products allow remote arbitrary code execution, privilege escalation, and remote denial of service.
- Who is affected
- Multiple IBM product deployments are affected.
- Urgency
- Critical; vulnerabilities enabling remote code execution and privilege escalation across IBM products require urgent remediation.
- Action
- Identify affected IBM products from CVE details and apply vendor-specific patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1094/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-414110.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-143800.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-260070.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-431980.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542930.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-499780.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-96970.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-535400.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542830.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-543690.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8661-4: Linux kernel vulnerabilitiesubuntu
- unknownUSN-8715-1: Linux kernel (Oracle) vulnerabilitiesubuntu
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilitiescert-bund
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- high[NEW] [high] Red Hat Enterprise Linux (Pillow): Multiple vulnerabilitiescert-bund
- high[NEW] [high] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri,…cert-bund
- medium[NEW] [medium] Eclipse Jetty: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] FasterXML Jackson: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM License Metric Tool: Multiple Vulnerabilities enable unspecified attackcert-bund
- criticalexploitedCVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerabilitycisa-kev
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis · 2026-08-14
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-08-13
- highCVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unve…nvd · 2026-08-12
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis · 2026-08-07
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Curl (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in HPE Aruba Networking products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Google Chrome (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in Mozilla products (02 September 2026)2026-09-02
- unknownMultiple vulnerabilities in SonicWall products (02 September 2026)2026-09-02