[UPDATE] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2618
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-115250.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-121510.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all scored CVEs.
- Low exploitation riskCVE-2026-136760.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-535500.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-542850.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-598690.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-598770.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-67330.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-67340.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-96750.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11525 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12151 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13676 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53550 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59869 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59877 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6733 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6734 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9675 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9678 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9679 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9697 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri,…cert-bund
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilitiescert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- highGHSA-4c8g-83qw-93j6: fast-uri vulnerable to host confusion via failed IDN canonicalizationghsa
- mediumGHSA-j3f2-48v5-ccww: protobufjs: Denial of Service via infinite loop in .proto option parsingghsa
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- highCVE-2026-59869: js-yaml: YAML merge-key chains can force quadratic CPU consumptionmsrc
- mediumCVE-2026-59877: protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.…nvd
- highCVE-2026-59869: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before…nvd
- highCVE-2026-13676: fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames f…nvd
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 29, 2026)cert-fr-avis
Recent advisories for IBM App Connect Enterprise
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] IBM App Connect Enterprise: Mehrere Schwachstellencert-bund · 2026-08-05
- high[UPDATE] [high] IBM App Connect Enterprise Certified Container: Multiple vulnerabilitiescert-bund · 2026-08-04
- medium[UPDATE] [mittel] IBM App Connect Enterprise (Axios): Mehrere Schwachstellencert-bund · 2026-08-04
- medium[NEW] [medium] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-08-03
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-07-31
- criticalCVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could al…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen Privilegieneskalation und Denial of Service2026-08-05
- medium[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung2026-08-05
- high[NEU] [hoch] Veeam ONE: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] Mozilla Firefox für Android: Schwachstelle ermöglicht Offenlegung von Informationen2026-08-05