Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems
IBM patched critical flaws in Financial Transaction Manager, including unauthenticated RCE vulnerabilities with CVSS scores up to 9.9.
IBM has released security fixes for its Financial Transaction Manager (FTM) for Red Hat OpenShift, addressing multiple critical vulnerabilities with CVSS scores up to 9.9. The most severe flaw, CVE-2026-18163, is an unauthenticated remote code execution vulnerability caused by unsafe deserialization. Successful exploitation could lead to payment fraud, data exposure, and full system compromise for financial organizations using the platform.