Multiple vulnerabilities in IBM products (July 24, 2026)
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
- Who is affected
- Deployments of IBM products are affected.
- Urgency
- Remediation is critical due to the severity of the vulnerabilities, including remote code execution, though exploitation status is currently unknown.
- Action
- Users should update their IBM products to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch IBM products
Get an email when a new IBM products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0933/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-535400.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-542830.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-505570.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Moderate exploitation riskCVE-2026-338711.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Low exploitation riskCVE-2026-489900.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-113830.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all scored CVEs.
- Low exploitation riskCVE-2026-454160.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-427661.00% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all scored CVEs.
- Low exploitation riskCVE-2026-90760.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] IBM WebSphere Application Server Liberty: Multiple vulnerabilities allow denial of servicecert-bund
- high[UPDATE] [high] IBM WebSphere Application Server and Application Server Liberty: Multiple vulnerabilitiescert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- highCVE-2026-11536: IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerabi…nvd
- criticalCVE-2026-11707: IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is a…nvd
- mediumCVE-2026-11383: IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is a…nvd
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] FasterXML Jackson: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[UPDATE] [high] OpenSSL: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Netty: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM WebSphere Application Server: Multiple vulnerabilitiescert-bund
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31