Multiple vulnerabilities in IBM products (June 26, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM products can lead to remote code execution and privilege escalation.
- Who is affected
- Users of affected IBM products.
- Urgency
- Immediate action is required due to the severity of the vulnerabilities.
- Action
- Update IBM products to the latest versions to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0810/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-363530.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-661990.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-25340.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-113830.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-420410.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-138670.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-424020.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-26680.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- criticalexploited[UPDATE] [critical] Oracle Fusion Middleware: Multiple Vulnerabilitiescert-bund
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian productsncsc-nl
- high[NEW] [high] Golang Go: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Golang Go-Module (Net, Image, Crypto): Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] IBM DB2: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilitiescert-bund
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)cert-fr-avis
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabiliti…cert-bund
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21