IBM Product Security Update Advisory
IBM has released security updates to address vulnerabilities found in several of its products.
Affected Products and Vulnerabilities
- IBM Sterling B2B Integrator, IBM Sterling File Gateway: CVE-2026-7769. This is an SQL injection vulnerability (an attack that manipulates database queries by exploiting input values).
- Aspera Desktop App: CVE-2026-11980, CVE-2026-14973. These are vulnerabilities that allow arbitrary code execution and arbitrary file writing through directory traversal.
- IBM WebSphere Application Server: CVE-2026-14446, CVE-2026-14512, CVE-2026-14528, CVE-2026-14974, CVE-2026-15325, CVE-2026-16184. These are vulnerabilities involving privilege escalation, insecure deserialization, exposure of sensitive information, arbitrary code execution, HTTP request smuggling, and authentication bypass.
- IBM Observability with Instana (Agent): CVE-2026-14893. This is a prototype pollution vulnerability in the Instana Node.Js tracer component.
- IBM WebSphere Application Server – Liberty: CVE-2026-14976, CVE-2026-15280, CVE-2026-14981, CVE-2026-15064, CVE-2026-15328, CVE-2026-16192. These are vulnerabilities involving remote code execution, path segment injection, denial of service, HTTP response smuggling, and HTTP request smuggling.
Impact
These vulnerabilities could lead to arbitrary code execution, remote code execution, privilege escalation, authentication bypass, exposure of sensitive information, and denial of service.
Action
IBM has announced that it has addressed these vulnerabilities through the latest version or the specified Interim Fix and APAR patches. Environments using the affected products and versions must be updated to the recommended patch versions.
Example Patch Versions
- CVE-2026-7769: IBM Sterling B2B Integrator, IBM Sterling File Gateway 6.2.0.6, 6.2.1.2, 6.2.2.1.
- CVE-2026-11980, CVE-2026-14973: Aspera Desktop App 1.1.0.
- CVE-2026-14446, CVE-2026-14512, CVE-2026-14528, CVE-2026-14974, CVE-2026-15325, CVE-2026-16184: IBM WebSphere Application Server 8.5.5.31 Or later, or 9.0.5.29 Or later, or the specified APAR Interim Fix.
- CVE-2026-14893: IBM Observability with Instana (Agent) 1.0.321 Or later.
- CVE-2026-14976, CVE-2026-15280: IBM WebSphere Application Server – Liberty 26.0.0.9 Or later, or the specified APAR Interim Fix.
- CVE-2026-14981, CVE-2026-15064, CVE-2026-15328: IBM WebSphere Application Server 8.5.5.31 Or later, 9.0.5.29 Or later, or IBM WebSphere Application Server – Liberty 26.0.0.8 Or later with the specified APAR Interim Fix.
- CVE-2026-16192: IBM WebSphere Application Server – Liberty 26.0.0.9 Or later, or the specified APAR Interim Fix.