IBM Product Security Update Advisory

IBM Product Security Update Advisory

Overview


A security update has been released to address vulnerabilities in IBM products. The affected products are Langflow OSS and IBM WebSphere Application Server – Liberty.

Affected Products and Vulnerabilities


  • CVE-2026-7524 has been identified in Langflow OSS versions 1.0.0 Through 1.9.1.
  • CVE-2026-7528 has been identified in Langflow OSS versions 1.0.0 Through 1.9.0.
  • CVE-2026-11806 was identified in WebSphere Application Server – Liberty versions 17.0.0.3 Through 26.0.0.6.

Resolved Vulnerabilities


  • CVE-2026-7524 is a remote code execution vulnerability in Langflow OSS.
  • CVE-2026-7528 is a denial-of-service and information disclosure vulnerability in Langflow OSS.
  • CVE-2026-11806 is an arbitrary file read vulnerability in IBM WebSphere Application Server Liberty.

Mitigation Steps


Vulnerability Patches are available through the latest updates. Langflow OSS must be updated to version 1.9.2, And WebSphere Application Server – Liberty must be updated to Liberty Fix Pack 26.0.0.7 Or later, or the APAR PH71719 Interim Fix must be applied.

Note


You must update to the latest version with the Vulnerability Patch according to the instructions on the reference site.