π¨ CVE-2025-36178
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
π@cveNotify
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Controller
Multiple vulnerabilities were addressed in IBM Controller version 11.2.0
π¨ CVE-2025-36421
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
π@cveNotify
IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Controller
Multiple vulnerabilities were addressed in IBM Controller version 11.2.0
π¨ CVE-2025-53837
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
π@cveNotify
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as content of HTML macros without further escaping and it is thus possible to close the HTML macro and inject script macros that are executed with programming rights. This has been patched in XWiki 14.10.2 and 15.0 RC1 by making sure that rendering output cannot close the surrounding HTML macro. A possible workaround is available. It is, in principle, possible to add escaping to all places where rendering output is used in wiki documents, but at the moment there is no list of them.
π@cveNotify
GitHub
XRENDERING-693: XHTML printer does not protect against closing HTML m⦠· xwiki/xwiki-rendering@92bc809
β¦acro in raw output
* Escape raw output to prevent the injection of `{{/html}}`.
* Escape raw output to prevent the injection of `{{/html}}`.
π¨ CVE-2025-61682
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
π@cveNotify
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
π@cveNotify
GitHub
Release SMW 7.0.0 Β· SemanticMediaWiki/SemanticMediaWiki
Released on June 4, 2026 - RELEASE NOTES
Note: The provided source code links do not include required dependencies. The recommended way to install Semantic MediaWiki is documented in the installati...
Note: The provided source code links do not include required dependencies. The recommended way to install Semantic MediaWiki is documented in the installati...
π¨ CVE-2026-10027
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
π@cveNotify
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to unauthenticated remote code execution (CVE-2026-10027)
IBM MQ has addressed a heap out-of-bounds write vulnerability in the queue manager's message decompression handling that could allow an unauthenticated remote attacker with network access to the listener port to execute arbitrary code
π¨ CVE-2026-10030
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
π@cveNotify
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Console is vulnerable to privilege escalation
IBM MQ has addressed a missing authorization check in the IBM MQ Console that could allow a remote authenticated user with read-only console access to create and start queue managers on the host
π¨ CVE-2026-10575
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10575)
IBM MQ has addressed an heap buffer overflow vulnerability when processing MQPUT operations with malformed distribution headers that could allow a remote authenticated attacker to cause a denial of service or potentially escalate privileges.
π¨ CVE-2026-10744
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
π@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
π@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation (CVE-2026-10744)
IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation when CONNAUTH is being used.
π¨ CVE-2026-10747
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
π@cveNotify
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing (CVE-2026β¦
IBM MQ Appliance has addressed a heap buffer overflow vulnerability in protocol message processing that could allow a remote attacker to cause a denial of service or execute arbitrary code prior to authentication.
π¨ CVE-2026-10751
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
π@cveNotify
IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
π@cveNotify
Ibm
Security Bulletin: IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-10751)
IBM MQ has addressed a Java deserialization filter bypass in the IBM MQ JMS client that could allow a remote authenticated attacker to execute arbitrary code
π¨ CVE-2026-10841
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
π@cveNotify
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
π@cveNotify
Ibm
Security Bulletin: Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. IBM WebSphere Liberty has been updated within IBM CICS TX Advanced to address these vulnerabilities.
π¨ CVE-2026-10853
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
π@cveNotify
IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-10853)
IBM MQ has addressed a heap buffer overflow vulnerability in the queue manager's cluster repository manager
π¨ CVE-2026-10858
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
π@cveNotify
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
π@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a denial of service attack (CVE-2026-10858)
IBM MQ for HPE NonStop is vulnerable to a denial of service issue caused by a heap buffer overflow.
π¨ CVE-2026-11375
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-11375)
IBM MQ has addressed a stack buffer overflow vulnerability in the queue manager's XA transaction handling that could allow a remote authenticated attacker to execute arbitrary code by sending a crafted transaction identifier
π¨ CVE-2026-11378
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
π@cveNotify
Ibm
Security Bulletin: IBM MQ queue manager is vulnerable to remote code execution (CVE-2026-11378)
IBM MQ has addressed an integer overflow vulnerability in the queue manager's object descriptor conversion that could allow a remote authenticated attacker to write zeros to arbitrary heap memory locations, leading to remote code execution.
π¨ CVE-2026-11381
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
π@cveNotify
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
π@cveNotify
Ibm
Security Bulletin: IBM MQ for HPE NonStop is vulnerable to a denial of service issue (CVE-2026-11381)
IBM MQ for HPE NonStop is vulnerable to a denial of service issue when using MQ distribution lists.
π¨ CVE-2026-11537
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
π@cveNotify
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
π@cveNotify
Ibm
Security Bulletin: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities.
π¨ CVE-2026-1025
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administrationβ¦
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
π¨ CVE-2026-1029
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administrationβ¦
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
π¨ CVE-2026-1031
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administrationβ¦
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.
π¨ CVE-2026-1037
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
π@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administrationβ¦
Multiple vulnerabilities affects IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Please refer below for vulnerability details, and remediation.