🚨 CVE-2026-17270
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-17273
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-17440
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17442
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17443
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17444
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
🚨 CVE-2026-17469
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [CVE-2026-17470, CVE-2026-17469]
IBM i is vulnerable to denial of service due to a buffer overflow and off-by-one write [CVE-2026-17470, CVE-2026-17469] in Line Printer Daemon (LPD) as described in the vulnerability details section.
🚨 CVE-2026-17470
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [CVE-2026-17470, CVE-2026-17469]
IBM i is vulnerable to denial of service due to a buffer overflow and off-by-one write [CVE-2026-17470, CVE-2026-17469] in Line Printer Daemon (LPD) as described in the vulnerability details section.
🚨 CVE-2026-17483
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
🎖@cveNotify
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
🎖@cveNotify
Ibm
Security Bulletin: IBM Db2 Mirror for i is affected by multiple vulnerabilities [CVE-2026-18567, CVE-2026-16660, CVE-2026-17483]
IBM Db2 Mirror for i is affected by multiple vulnerabilities as described in the vulnerability details section.
🚨 CVE-2026-17499
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-17621
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge…
Langflow uses filesystem path construction as part of several components and API endpoints, including the Directory component, the Knowledge Base connector ingestion endpoint, and the Knowledge Base flow component. In the Directory component, user-supplied…
🚨 CVE-2026-17622
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge…
Langflow uses filesystem path construction as part of several components and API endpoints, including the Directory component, the Knowledge Base connector ingestion endpoint, and the Knowledge Base flow component. In the Directory component, user-supplied…
🚨 CVE-2026-17627
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
🎖@cveNotify
Ibm
Security Bulletin: Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint
Langflow provides a voice-mode feature through a WebSocket API endpoint that accepts a flow identifier as a URL path parameter and uses it to retrieve the target flow description and persist conversation messages against that flow. The endpoint authenticates…
🚨 CVE-2026-17631
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
🎖@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
🎖@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components
Langflow uses outbound HTTP request functionality as part of several flow components, including components for LM Studio, Home Assistant, DeepSeek, xAI, Glean, HuggingFace Inference API, Ollama, LiteLLM, and Docling Serve. These components accept user-supplied…
🚨 CVE-2026-18073
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-18076
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
🚨 CVE-2026-18078
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerability in Save Restore [CVE-2026-18078]
IBM i is vulnerable to denial of service due to an integer overflow [CVE-2026-18078] in Save Restore as described in the vulnerability details section.
🚨 CVE-2026-18175
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [CVE-2026-18175…
IBM i is vulnerable to manipulation of database transactions due to improper authorization [CVE-2026-18175] and allowing unathorized access due to improper validation [CVE-2026-18221] in Distributed Data Management (DDM) / Distributed Relational Database…
🚨 CVE-2026-18221
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [CVE-2026-18175…
IBM i is vulnerable to manipulation of database transactions due to improper authorization [CVE-2026-18175] and allowing unathorized access due to improper validation [CVE-2026-18221] in Distributed Data Management (DDM) / Distributed Relational Database…
🚨 CVE-2026-18341
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
🎖@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
🎖@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Buffer Overflow Vulnerability [CVE-2026-18341]
IBM i is vulnerable to a buffer overflow due to an integer underflow [CVE-2026-18341] as described in the vulnerability details section.
🚨 CVE-2026-18486
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
🎖@cveNotify
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
🎖@cveNotify
Ibm
Security Bulletin: IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution
IBM ContextForge MCP Gateway allows authenticated users with developer privileges to supply a jq program in the tool jsonpath_filter field that executes unrestricted built-in such as `$ENV` inside the server process, exposing environment variables including…