IBM security advisory (AV26-1022)
Canada's Cyber Centre says IBM DataPower Gateway and Langflow OSS need patches, including XSS CVE-2026-14990.
On October 8, 2026, the Canadian Centre for Cyber Security issued advisory AV26-1022. IBM DataPower Gateway releases through 10.5.0.22, 10.6.0.10, 10.6.6, and 11.0.0.2 are affected, including cross-site scripting tracked as CVE-2026-14990, plus other unspecified CVEs. Langflow OSS versions 1.0.0 through 1.12.2 are affected by multiple vulnerabilities. The centre urges administrators to review IBM’s bulletins and apply updates. The advisory does not report exploitation in the wild.