# IBM vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 34 IBM CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 4 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 34 IBM CVEs published between 2026-06-15 and 2026-09-15. The busiest month was 2026-09 (22 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 34 of 34 tracked IBM CVEs.

- [CVE-2026-81941](https://intel.threadlinqs.com/cve/CVE-2026-81941) — HIGH 8.8 · EPSS 0.8% · 2026-09-10
- [CVE-2026-82098](https://intel.threadlinqs.com/cve/CVE-2026-82098) — HIGH 8.8 · EPSS 0.8% · 2026-09-10
- [CVE-2026-81940](https://intel.threadlinqs.com/cve/CVE-2026-81940) — HIGH 8.8 · EPSS 0.5% · 2026-09-10
- [CVE-2026-82092](https://intel.threadlinqs.com/cve/CVE-2026-82092) — HIGH 8.8 · EPSS 0.5% · 2026-09-10
- [CVE-2026-82095](https://intel.threadlinqs.com/cve/CVE-2026-82095) — HIGH 8.8 · EPSS 0.5% · 2026-09-10
- [CVE-2026-18169](https://intel.threadlinqs.com/cve/CVE-2026-18169) — CRITICAL 9.9 · EPSS 0.5% · 2026-09-22
- [CVE-2026-84889](https://intel.threadlinqs.com/cve/CVE-2026-84889) — HIGH 8.8 · EPSS 0.5% · 2026-09-10
- [CVE-2026-18163](https://intel.threadlinqs.com/cve/CVE-2026-18163) — CRITICAL 9.8 · EPSS 0.5% · 2026-09-22
- [CVE-2026-18162](https://intel.threadlinqs.com/cve/CVE-2026-18162) — CRITICAL 9.8 · EPSS 0.5% · 2026-09-22
- [CVE-2026-86093](https://intel.threadlinqs.com/cve/CVE-2026-86093) — HIGH 7.5 · EPSS 0.5% · 2026-09-10
- [CVE-2026-82100](https://intel.threadlinqs.com/cve/CVE-2026-82100) — CRITICAL 9.6 · EPSS 0.4% · 2026-09-10
- [CVE-2026-9072](https://intel.threadlinqs.com/cve/CVE-2026-9072) — HIGH 8.1 · EPSS 0.4% · 2026-06-22
- [CVE-2026-82107](https://intel.threadlinqs.com/cve/CVE-2026-82107) — CRITICAL 9.6 · EPSS 0.4% · 2026-09-10
- [CVE-2026-82097](https://intel.threadlinqs.com/cve/CVE-2026-82097) — HIGH 8.8 · EPSS 0.4% · 2026-09-10
- [CVE-2026-8646](https://intel.threadlinqs.com/cve/CVE-2026-8646) — HIGH 7.4 · EPSS 0.4% · 2026-06-22
- [CVE-2026-80423](https://intel.threadlinqs.com/cve/CVE-2026-80423) — HIGH 8.8 · EPSS 0.3% · 2026-09-23
- [CVE-2026-9071](https://intel.threadlinqs.com/cve/CVE-2026-9071) — HIGH 7.5 · EPSS 0.3% · 2026-06-22
- [CVE-2026-9320](https://intel.threadlinqs.com/cve/CVE-2026-9320) — MEDIUM 5.9 · EPSS 0.3% · 2026-06-22
- [CVE-2026-7664](https://intel.threadlinqs.com/cve/CVE-2026-7664) — CRITICAL 9.8 · EPSS 0.3% · 2026-06-22
- [CVE-2026-8858](https://intel.threadlinqs.com/cve/CVE-2026-8858) — HIGH 7.5 · EPSS 0.2% · 2026-06-22
- [CVE-2026-18173](https://intel.threadlinqs.com/cve/CVE-2026-18173) — LOW 3.7 · EPSS 0.2% · 2026-09-22
- [CVE-2026-9006](https://intel.threadlinqs.com/cve/CVE-2026-9006) — HIGH 7.4 · EPSS 0.2% · 2026-06-22
- [CVE-2026-86087](https://intel.threadlinqs.com/cve/CVE-2026-86087) — MEDIUM 4.3 · EPSS 0.2% · 2026-09-10
- [CVE-2026-18132](https://intel.threadlinqs.com/cve/CVE-2026-18132) — MEDIUM 6.5 · EPSS 0.2% · 2026-09-22
- [CVE-2026-87958](https://intel.threadlinqs.com/cve/CVE-2026-87958) — HIGH 8.1 · EPSS 0.2% · 2026-09-10
- [CVE-2026-18172](https://intel.threadlinqs.com/cve/CVE-2026-18172) — HIGH 7.4 · EPSS 0.2% · 2026-09-22
- [CVE-2026-18161](https://intel.threadlinqs.com/cve/CVE-2026-18161) — MEDIUM 4.3 · EPSS 0.2% · 2026-09-22
- [CVE-2026-18170](https://intel.threadlinqs.com/cve/CVE-2026-18170) — MEDIUM 6.5 · EPSS 0.2% · 2026-09-22
- [CVE-2026-7253](https://intel.threadlinqs.com/cve/CVE-2026-7253) — MEDIUM 5.3 · EPSS 0.2% · 2026-06-22
- [CVE-2026-18176](https://intel.threadlinqs.com/cve/CVE-2026-18176) — HIGH 7.4 · EPSS 0.1% · 2026-09-22
- [CVE-2026-8059](https://intel.threadlinqs.com/cve/CVE-2026-8059) — MEDIUM 6.1 · EPSS 0.1% · 2026-06-22
- [CVE-2026-9610](https://intel.threadlinqs.com/cve/CVE-2026-9610) — LOW 2.3 · EPSS 0.1% · 2026-06-22
- [CVE-2026-8636](https://intel.threadlinqs.com/cve/CVE-2026-8636) — MEDIUM 5.5 · EPSS 0.1% · 2026-06-22
- [CVE-2026-7366](https://intel.threadlinqs.com/cve/CVE-2026-7366) — MEDIUM 4.2 · 2026-08-12

## Products affected

Threadlinqs normalises CPE and CNA product records across all 34 CVEs; 13 distinct IBM products are affected. The most frequently affected:

- Financial Transaction Manager (FTM) for RedHat OpenShift — 9 CVEs
- DataStage on Cloud Pak for Data — 7 CVEs
- Langflow OSS — 4 CVEs
- WebSphere Application Server — 4 CVEs
- Datacap — 3 CVEs
- Datacap Navigator — 3 CVEs
- Db2 — 3 CVEs
- WebSphere Application Server - Liberty — 3 CVEs
- i — 2 CVEs
- DataPower Gateway 10.5.0 — 1 CVE
- DataPower Gateway 10.6.0 — 1 CVE
- DataPower Gateway 11.0.0 — 1 CVE
- Watson Speech Services Cartridge — 1 CVE

## Threat activity

4 tracked threat campaigns reference IBM products or exploit IBM CVEs:

- [CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code Injection Chain)](https://intel.threadlinqs.com/threat/TL-2026-1893) — CRITICAL — 2026-08-05
- [FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai](https://intel.threadlinqs.com/threat/TL-2026-1669) — HIGH — 2026-07-24
- [CVE-2026-5027: Path Traversal Arbitrary File Write in Langflow AI Dev Platform (upload_user_file) Exploited in the Wild for Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-0766) — HIGH — 2026-06-10
- [IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)](https://intel.threadlinqs.com/threat/TL-2026-0650) — CRITICAL — 2026-06-01

## How to prioritise IBM patching

This order follows the data Threadlinqs holds for IBM, not a generic severity checklist:

- No IBM CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-81941](https://intel.threadlinqs.com/cve/CVE-2026-81941) (0.8%), [CVE-2026-82098](https://intel.threadlinqs.com/cve/CVE-2026-82098) (0.8%), [CVE-2026-81940](https://intel.threadlinqs.com/cve/CVE-2026-81940) (0.5%).
- 6 CVEs score Critical and 17 High on CVSS v3 (maximum 9.9, average 7.4); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/ibm
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
