IBM X-Force
ibm-xforce · B · active
https://www.ibm.com/think/x-force
IBM X-Force Threat Intelligence; annual X-Force Threat Index. URL CORRECTED 2026-05-08: legacy securityintelligence.com 301-redirects to www.ibm.com/think/security; the X-Force-specific sub-page is /think/x-force. The hub is a marketing portal rather than a dated blog — sub-agents reliably mis-report 'no items' because per-post dates are sparse in the listing. Drill into the X-Force Threat Intelligence Index (annual) and any podcast/webinar entries with explicit dates. Reliability MEDIUM until IBM publishes a clean dated archive again. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py url https://www.ibm.com/think/x-force (listing) then bridge url <article /think/x-force/<slug>> for body. AVOID: WebFetch now 403s on BOTH the /think/x-force index AND article pages — skip WebFetch, go straight to the bridge. Listing has no inline per-post dates; read dateModified from the article HTML.. | 2026-07-05 admiralty audit: B — original vendor threat research; listing lacks inline dates so read dateModified from the article HTML via bridge. MEDIUM->B, stays active.
Cited in 8 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 6).
- CVE-2026-9198 — a third Langflow pre-auth code-execution path reaches CISA KEV: an unauthenticated auto-login endpoint mints a superuser token, and code validation executes what it is handed2026-08-05
- Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply2026-08-02
- 2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks2026-08-02
- CVE-2026-14512 / CVE-2026-14446 — IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- Langflow correction — 1.10.1 is not the endpoint: CVE-2026-14499 needs 1.10.2, and CVE-2026-0770 has no AUTO_LOGIN precondition2026-07-26
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)2026-05-29
- CVE-2026-32996 & CVE-2026-32997 — Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE (CVSS 9.8)2026-05-25