[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2618
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-115250.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-121510.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all scored CVEs.
- Low exploitation riskCVE-2026-136760.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-535500.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-542850.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-598690.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-598770.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-67330.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-67340.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-96750.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11525 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12151 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13676 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53550 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59869 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59877 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6733 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6734 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9675 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9678 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9679 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9697 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri,…cert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilitiescert-bund
- highGHSA-4c8g-83qw-93j6: fast-uri vulnerable to host confusion via failed IDN canonicalizationghsa
- mediumGHSA-j3f2-48v5-ccww: protobufjs: Denial of Service via infinite loop in .proto option parsingghsa
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- highCVE-2026-59869: js-yaml: YAML merge-key chains can force quadratic CPU consumptionmsrc
- mediumCVE-2026-59877: protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.…nvd
- highCVE-2026-59869: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before…nvd
- highCVE-2026-13676: fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames f…nvd
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 29, 2026)cert-fr-avis
Recent advisories for IBM App Connect Enterprise
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-08-03
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-07-31
- criticalCVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could al…nvd · 2026-07-30
- highCVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could al…nvd · 2026-07-30
- highCVE-2026-14519: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could al…nvd · 2026-07-30
- highCVE-2026-12947: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores p…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- high[NEU] [hoch] rclone: Mehrere Schwachstellen2026-08-03
- medium[NEU] [mittel] N-able N-Central: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen2026-08-03
- high[NEU] [hoch] Bouncy Castle: Mehrere Schwachstellen2026-08-03
- high[NEU] [hoch] Wazuh: Mehrere Schwachstellen2026-08-03
- high[NEU] [hoch] IBM Langflow Desktop: Mehrere Schwachstellen2026-08-03