Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1165/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-755950.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-499780.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-409310.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-524710.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-55880.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-330363.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-449064.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542640.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-501420.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-596510.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Netty: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Bouncy Castle BC-JAVA: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Enterprise Linux (Apicurio Registry): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-u…cert-bund
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Eclipse Jetty: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Bouncy Castle: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apache CXF: Mehrere Schwachstellencert-bund
- criticalGHSA-c4c3-7fpv-j4q5: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslC…ghsa
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (11 septembre 2026)2026-09-11
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (11 septembre 2026)2026-09-11
- unknownMultiples vulnérabilités dans GitLab (11 septembre 2026)2026-09-11
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (11 septembre 2026)2026-09-11
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (11 septembre 2026)2026-09-11