[UPDATE] [mittel] IBM App Connect Enterprise (Axios): Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1450
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-420330.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all scored CVEs.
- Low exploitation riskCVE-2026-420340.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-420350.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-420360.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-420370.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-420380.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-420390.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-420400.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-420410.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-420420.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42033 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42034 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42036 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42037 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42038 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42041 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42044 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabiliti…cert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 3, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (June 26, 2026)cert-fr-avis
Recent advisories for IBM App Connect
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] IBM App Connect Enterprise: Mehrere Schwachstellencert-bund · 2026-08-05
- high[UPDATE] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellencert-bund · 2026-08-05
- high[UPDATE] [high] IBM App Connect Enterprise Certified Container: Multiple vulnerabilitiescert-bund · 2026-08-04
- medium[NEW] [medium] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-08-03
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund · 2026-07-31
- criticalCVE-2026-15435: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could al…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen Privilegieneskalation und Denial of Service2026-08-05
- medium[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung2026-08-05
- high[NEU] [hoch] Veeam ONE: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] Mozilla Firefox für Android: Schwachstelle ermöglicht Offenlegung von Informationen2026-08-05