Multiples vulnérabilités dans les produits IBM (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM products allow remote arbitrary code execution, remote denial of service, and data integrity breaches.
- Who is affected
- Deployments of affected IBM products across an unspecified range of versions.
- Urgency
- High priority; remote code execution and data integrity attacks are possible, though exploitation status is not documented.
- Action
- Identify affected IBM product versions and apply vendor security patches for CVE-2026-5588, CVE-2026-41254, CVE-2025-9714, CVE-2026-24734, CVE-2025-66614, CVE-2026-16243, CVE-2026-47010, and CVE-2026-22013.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1121/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-412540.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-97140.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-247340.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-666140.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-162430.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470100.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-220130.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470570.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-220180.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund
- high[UPDATE] [hoch] Bouncy Castle BC-JAVA: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apache log4j: Mehrere Schwachstellen ermöglichen Manipulation von Dateiencert-bund
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (11 septembre 2026)cert-fr-avis
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- high[NEU] [hoch] SAP Patch Day September 2026: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)cert-fr-avis
- medium[UPDATE] [mittel] FreeType: Schwachstelle ermöglicht nicht spezifizierten Angriffcert-bund
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Edge (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans MISP (14 septembre 2026)2026-09-14