ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-18078 | Low | 0.3% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus… | |
| CVE-2026-18887 | Low | 0.3% | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sen… | |
| CVE-2026-10571 | Low | 0.3% | 5.7 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected… | |
| CVE-2026-17476 | Low | 0.3% | 4.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17424 | Low | 0.3% | 4.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to b… | |
| CVE-2026-16871 | Low | 0.3% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2026-17616 | Low | 0.3% | 6.8 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2025-36221 | Low | 0.3% | 5.3 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl… | |
| CVE-2026-16866 | Low | 0.3% | 4.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17420 | Low | 0.3% | 6.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-16905 | Low | 0.3% | 5.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… | |
| CVE-2026-16825 | Low | 0.3% | 4.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-17468 | Low | 0.3% | 5.3 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to f… | |
| CVE-2026-13477 | Low | 0.3% | 4.7 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00… | |
| CVE-2026-7364 | Low | 0.3% | 3.1 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10… | |
| CVE-2026-16713 | Low | 0.3% | 4.3 | IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a re… | |
| CVE-2026-16892 | Low | 0.3% | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-17222 | Low | 0.3% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modi… | |
| CVE-2026-16964 | Low | 0.2% | 6.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to i… | |
| CVE-2026-18715 | Low | 0.2% | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2026-19448 | Low | 0.2% | 6.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerab… | |
| CVE-2026-4942 | Low | 0.2% | 5.9 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specificall… | |
| CVE-2026-18341 | Low | 0.2% | 6.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corr… | |
| CVE-2026-17419 | Low | 0.2% | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modi… | |
| CVE-2026-12762 | Low | 0.2% | 5.3 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could a… | |
| CVE-2026-17649 | Low | 0.2% | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive i… | |
| CVE-2026-18849 | Low | 0.2% | 6.8 | IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BM… | |
| CVE-2026-16480 | Low | 0.2% | 4.3 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an impro… | |
| CVE-2026-18144 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-17274 | Low | 0.2% | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-18102 | Low | 0.2% | 3.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to over… | |
| CVE-2026-86087 | Low | 0.2% | 4.3 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenti… | |
| CVE-2026-11937 | Low | 0.2% | 3.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-18531 | Low | 0.2% | 5.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to … | |
| CVE-2026-16941 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify ce… | |
| CVE-2026-16180 | Low | 0.2% | 5.7 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.… | |
| CVE-2026-18068 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive i… | |
| CVE-2026-3157 | Low | 0.2% | 4.3 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2… | |
| CVE-2025-64649 | Low | 0.2% | 5.9 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unautho… | |
| CVE-2026-9327 | Low | 0.2% | 6.3 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user … | |
| CVE-2026-16846 | Low | 0.2% | 6.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-18671 | Low | 0.2% | 6.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a Ne… | |
| CVE-2024-22349 | Low | 0.2% | 4.0 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allow… | |
| CVE-2026-17268 | Low | 0.2% | 6.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-17270 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of s… | |
| CVE-2026-17074 | Low | 0.2% | 3.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-17469 | Low | 0.2% | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause… | |
| CVE-2026-8058 | Low | 0.2% | 4.5 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows … | |
| CVE-2026-18148 | Low | 0.2% | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inje… | |
| CVE-2026-17209 | Low | 0.2% | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… |