IBM Product Security Update Advisory

IBM Product Security Update Advisory

Overview


IBM has released security updates to address vulnerabilities in several of its products. The affected products are Langflow OSS, IBM WebSphere Application Server, IBM Storage Protect Client, IBM Storage Protect Snapshot for Windows, and IBM i.

Key Vulnerabilities


  • CVE-2026-10561 is a remote code execution vulnerability in Langflow OSS.
  • CVE-2026-10845 is an authentication bypass vulnerability in IBM WebSphere Application Server.
  • CVE-2026-12628 is an authentication bypass vulnerability in IBM Storage Protect Snapshot for Windows.
  • CVE-2026-7664 is an authentication bypass vulnerability in Langflow OSS.
  • CVE-2026-8620 is an HTTP request smuggling vulnerability in IBM WebSphere Application Server Liberty.
  • CVE-2026-8633, CVE-2026-8858, and CVE-2026-9072 are remote code execution vulnerabilities in IBM WebSphere Application Server Liberty.
  • CVE-2026-10852 is a denial-of-service vulnerability in IBM WebSphere Application Server Liberty.
  • CVE-2026-9006 is a server-side request forgery vulnerability in IBM WebSphere Application Server.

Affected Products and Versions


  • Langflow OSS versions 1.0.0 Through 1.9.3 Are affected by CVE-2026-10561.
  • Langflow OSS versions 1.0.0 Through 1.8.4 Are affected by CVE-2026-7664.
  • IBM WebSphere Application Server versions 8.5 And 9.0 Are affected by CVE-2026-10845 and CVE-2026-9006.
  • IBM Storage Protect Client versions 8.1.0.0 Through 8.2.1.0 And IBM Storage Protect Snapshot for Windows versions 8.1.0.0 Through 8.2.1.0 Are affected by CVE-2026-12628.
  • IBM i versions 7.3, 7.4, 7.5, And 7.6 Are affected by CVE-2026-8620, CVE-2026-8633, CVE-2026-8858, CVE-2026-9072, and CVE-2026-10852.

Mitigation Measures


  • For Langflow OSS, update to version 1.9.4 Or later to address CVE-2026-10561.
  • For CVE-2026-7664, update Langflow OSS to version 1.9.1 Or later.
  • Update IBM Storage Protect Backup-Archive Client to version 8.2.1.1 Or later.
  • Apply the appropriate PTF for each version of IBM i. Apply SJ10122 for IBM i 7.6, SJ10121 for 7.5, SJ10120 for 7.4, And SJ10119 for 7.3.
  • Apply patches for IBM WebSphere Application Server and CVE-2026-9006 and CVE-2026-10845 according to the instructions on the reference site.

Note


IBM recommends updating to the latest version or applying the announced patches.