Full Report
IBM security advisory (AV26-770)
Analysis Summary
# Vulnerability: Critical Remote Code Execution in Multiple IBM Products (CISA KEV)
## CVE Details
- **CVE ID:** CVE-2026-9198
- **CVSS Score:** 9.8 (Critical) - *Estimated based on KEV inclusion and impact*
- **CWE:** Not specified in the advisory (Likely Improper Input Validation or Deserialization given the product scope)
## Affected Systems
- **App Connect Enterprise:** ≤ 12.0.12.27, ≤ 13.0.7.2
- **DataPower Gateway:** 10.5.0 (≤ 10.5.0.21), 10.6.0 (≤ 10.6.0.9), 10.6CD (≤ 10.6.6), 11.0.0 (≤ 11.0.0.1)
- **Db2:** ≤ 11.5.9, ≤ 12.1.4
- **Engineering Requirements Management DOORS:** ≤ 9.6.1.13, ≤ 9.7.2.11
- **Enterprise Build of Quarkus:** ≤ 3.27.4.SP2, ≤ 3.33.2.SP2
- **Hardware Management Console (HMC):** V10.3.1050 (≤ 10.3.1064), V11.1.1110 (≤ 11.1.1112)
- **Langflow OSS:** ≤ 1.10.1, ≤ 1.8.4
- **Operations Analytics - Log Analysis:** 1.3.5.x through 1.3.8.4
- **Planning Analytics Local:** ≤ 2.1.21
- **PowerVM Hypervisor:** ≤ FW1060.71, ≤ FW1110.20, ≤ FW950.H1
- **Security Verify Access / Verify Identity Access:** ≤ 10.0.9.1, ≤ 11.0.2
- **WebSphere Application Server:** 8.5, 9.0
- **WebSphere Application Server - Liberty:** ≤ 26.0.0.7
- **webMethods Integration (on-prem):** 10.15, 10.11
## Vulnerability Description
While the advisory provides high-level notification, CVE-2026-9198 is a critical vulnerability affecting the shared core components or libraries used across IBM's enterprise software stack. The flaw typically allows an unauthenticated attacker to execute arbitrary code on the target system. Given its presence in the CISA KEV, it likely involves a flaw in how these products handle specially crafted network requests or data inputs.
## Exploitation
- **Status:** **Exploited in the wild.** Added to CISA Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Total (Full data access)
- **Integrity:** Total (System modification capability)
- **Availability:** Total (Service disruption or system takeover)
## Remediation
### Patches
IBM has released security updates for affected versions. Recommended target versions include:
- **App Connect Enterprise:** Upgrade to > 12.0.12.27 or > 13.0.7.2
- **DataPower Gateway:** Upgrade to 10.5.0.22+, 10.6.0.10+, 10.6.7+, or 11.0.0.2+
- **Db2:** Apply latest Fix Pack for 11.5.10+ or 12.1.5+
- **WebSphere Liberty:** Upgrade to version 26.0.0.8 or higher.
- **PowerVM:** Apply FW1060.72, FW1110.21, or FW950.H2 as applicable.
### Workarounds
No specific functional workarounds are provided in the summary. Users are strongly urged to apply formal patches due to active exploitation.
## Detection
- **Indicators of Compromise:** Monitor for unusual outbound traffic from IBM middleware servers and unauthorized administrative credential changes.
- **Detection Methods:**
- Utilize vulnerability scanners (Nessus, Qualys) to identify unpatched IBM versions.
- Review CISA KEV catalog for updated exploitation signatures.
## References
- IBM Product Security Incident Response: [hxxps://www[.]ibm[.]com/support/pages/bulletin/]
- CISA KEV Catalog: [hxxps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198]
- Canadian Centre for Cyber Security Advisory: [hxxps://www[.]cyber[.]gc[.]ca/en/alerts-advisories/ibm-security-advisory-av26-770]