Multiple vulnerabilities in IBM products (July 24, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
- Who is affected
- Deployments of IBM products are affected.
- Urgency
- Remediation is critical due to the severity of the vulnerabilities, including remote code execution, though exploitation status is currently unknown.
- Action
- Users should update their IBM products to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch IBM products
Get an email when a new IBM products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0933/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-535400.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542830.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505570.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489900.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-113830.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-454160.86% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-427661.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-90760.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] IBM WebSphere Application Server und Application Server Liberty: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] IBM WebSphere Application Server: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] FasterXML Jackson: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Netty: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund
- unknownMultiples vulnérabilités dans les produits IBM (11 septembre 2026)cert-fr-avis
- high[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund
Recent advisories for IBM products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis · 2026-08-14
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-08-13
- highCVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unve…nvd · 2026-08-12
- unknownMultiple vulnerabilities in IBM products (August 07, 2026)cert-fr-avis · 2026-08-07
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Edge (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans MISP (14 septembre 2026)2026-09-14