IBM Support security bulletins
ibm-support-security-bulletins · A · candidate
Added 2026-10-02: CNA-level primary for IBM products, including Langflow OSS; dated, structured per-CVE vectors and affected/fixed tables per branch; discovery has so far come only through NCSC-NL relays. RECIPE: `python3 tools/fetch_source.py url <bulletin URL>` returns the full body (`extract` DROPPED rows of the IBM MQ remediation table); slug-form support-page URLs per bulletin. (2026-10-02T0404Z-intel)
Cited in 4 entries
Citation cadence
Citation days per ISO week (10 weeks of coverage span, total 3).
- CVE-2026-14512 / CVE-2026-14446, IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- CVE-2026-9170, IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)2026-05-29
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29