CVE-2026-2310IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data Exploitation status Not known exploited Fix YesAffected product W webMethods Integration Server Published 09/10/2026 Severity High CVE-2026-19646Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent Exploitation status Not known exploited Fix YesAffected product C Common Licensing Published 09/10/2026 Severity Critical CVE-2026-75624IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/10/2026 Severity High CVE-2026-75777Multiple vulnerabilities in IBM Aspera Enterprise Webapps Exploitation status Not known exploited Fix YesAffected product A Aspera Enterprise WebApps Published 09/10/2026 Severity High CVE-2026-76059Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-78569Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-78571Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-78573IBM ContextForge MCP Gateway is affected by use of default credentials Exploitation status Not known exploited Fix YesAffected product C ContextForge MCP Gateway Published 09/10/2026 Severity Critical CVE-2026-78575Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Medium CVE-2026-79724Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Critical CVE-2026-79725Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Medium CVE-2026-79742Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-80378DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-80380DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-80434DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-80424DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not confirmed Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity Critical CVE-2026-80436DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81204Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Critical CVE-2026-81207DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81210DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not confirmed Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81211Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-81941Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-81268Langflow is vulnerable to authentication bypass and insufficient session expiration Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-81540DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not confirmed Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81550DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81551DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not confirmed Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81554DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-81940Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-82092DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-82095DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-82097DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not confirmed Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-82098DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-82099DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity High CVE-2026-82100DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity Critical CVE-2026-82107DataStage on Cloud Pak for Data has several vulnerabilities due to open source software Exploitation status Not known exploited Fix YesAffected product D DataStage on Cloud Pak for Data Published 09/10/2026 Severity Critical CVE-2026-84889A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity High CVE-2026-86087IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system Exploitation status Not known exploited Fix YesAffected product D Db2 Published 09/10/2026 Severity Medium CVE-2026-86093IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions Exploitation status Not known exploited Fix YesAffected product D Db2 Published 09/10/2026 Severity High CVE-2026-87958IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions Exploitation status Not known exploited Fix YesAffected product D Db2 Published 09/10/2026 Severity High CVE-2026-85025Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Critical CVE-2026-9667IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities Exploitation status Not confirmed Fix YesAffected product W WebSphere Application Server Published 09/10/2026 Severity Medium CVE-2026-9176IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities Exploitation status Not known exploited Fix YesAffected product W WebSphere Application Server Published 09/10/2026 Severity Medium CVE-2026-9225Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/10/2026 Severity Medium CVE-2026-9327IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities Exploitation status Not known exploited Fix YesAffected product W WebSphere Application Server Published 09/10/2026 Severity Medium CVE-2026-9336IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities Exploitation status Not confirmed Fix YesAffected product W WebSphere Application Server Published 09/10/2026 Severity Medium CVE-2026-9338IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities Exploitation status Not known exploited Fix YesAffected product W WebSphere Application Server Published 09/10/2026 Severity Medium CVE-2026-19625IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities Exploitation status Not known exploited Fix YesAffected product E Enterprise Build of Quarkus Published 09/08/2026 Severity Medium CVE-2026-19651IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities Exploitation status Not known exploited Fix YesAffected product E Enterprise Build of Quarkus Published 09/08/2026 Severity High CVE-2026-13297Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access Exploitation status Not known exploited Fix YesAffected product V Verify Identity Access Published 09/04/2026 Severity High CVE-2026-14350Vulnerabilities exists in IBM Cloud Pak for Data System Exploitation status Not known exploited Fix YesAffected product C Cloud Pak for Data System Published 09/04/2026 Severity Medium CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-16180IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-16660IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] Exploitation status Not known exploited Fix YesAffected product D Db2 Mirror for i Published 09/04/2026 Severity Medium CVE-2026-16689IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-16693IBM i is Affected By Cryptographic Algorithm Weakness in DCM [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-16826IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-16892IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-16941IBM i is Affected By An Incorrect Authorization Vulnerability [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17057IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17207IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17255IBM i is Affected By Denial of Service Vulnerability [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17259IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17270IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17273IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17274IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17440IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-17442IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-17443IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-17444IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs Exploitation status Not known exploited Fix YesAffected product A App Connect Enterprise Published 09/04/2026 Severity Medium CVE-2026-17469IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17470IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17483IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] Exploitation status Not known exploited Fix YesAffected product D Db2 Mirror for i Published 09/04/2026 Severity Medium CVE-2026-17499IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-17627Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-17622Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-17631Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-18073IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-18078IBM i is Affected By Denial of Service Vulnerability in Save Restore [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-18076IBM i is Affected By Multiple Vulnerabilities in Debug Server Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-18175IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity High CVE-2026-18221IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity High CVE-2026-18341IBM i is Affected By Buffer Overflow Vulnerability [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-18486IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution Exploitation status Not known exploited Fix YesAffected product C ContextForge MCP Gateway Published 09/04/2026 Severity High CVE-2026-18489IBM ContextForge Translate is affected by cross-client credential context confusion Exploitation status Not known exploited Fix YesAffected product C ContextForge MCP Gateway - Translate utility Published 09/04/2026 Severity High CVE-2026-18567IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] Exploitation status Not known exploited Fix YesAffected product D Db2 Mirror for i Published 09/04/2026 Severity Medium CVE-2026-18658IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed Exploitation status Not known exploited Fix YesAffected product O Operational Decision Manager Published 09/04/2026 Severity Critical CVE-2026-18858IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Low CVE-2026-18887IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE [] Exploitation status Not known exploited Fix YesAffected product I i Published 09/04/2026 Severity Medium CVE-2026-19298Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity High CVE-2026-19301Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity High CVE-2026-18905IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation Exploitation status Not known exploited Fix YesAffected product C ContextForge MCP Gateway (`mcp-contextforge-gateway`) Published 09/04/2026 Severity High CVE-2026-19274IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image Exploitation status Not known exploited Fix YesAffected product O Observability with Instana (Agent) Published 09/04/2026 Severity Critical CVE-2026-19283IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image Exploitation status Not known exploited Fix YesAffected product O Observability with Instana (Agent) Published 09/04/2026 Severity High CVE-2026-19300Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity High CVE-2026-19299Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components Exploitation status Not known exploited Fix YesAffected product L Langflow OSS Published 09/04/2026 Severity Medium