ZeroHour

Vulnerabilities

257 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87958
+2 in the same advisory: …86093 …86087
Privileged-user denial-of-service flaw in IBM Db2 11.5 and 12.1

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a denial-of-service vulnerability (CWE-269, improper privilege management) in which a specific functionality on a Db2 server can be disabled. The flaw is triggered over the network by an authenticated user holding privileges on the Db2 server — the CVSS vector grades required privileges as low (PR:L) — and requires no user interaction, under certain conditions on the server. A successful attacker can disable that functionality, hitting availability; the 8.1 High CVSS vector also scores high integrity impact (C:N/I:H/A:H), suggesting the affected functionality can be left in a modified or disabled state. Any organization running the listed Db2 11.5.x or 12.1.x releases is potentially affected, though exploitation requires an account with privileges on the database server. There is no evidence of exploitation: the flaw is not in CISA KEV, and no public proof-of-concept is known.

Do: Check IBM's PSIRT advisory for CVE-2026-87958 to identify the fixed fix pack or interim-fix level (not specified in the available data) and plan upgrades for all 11.5.x and 12.1.x Db2 deployments. As an interim mitigation, restrict which accounts hold administration privileges on Db2 servers and audit recent configuration changes to the affected functionality. Prioritize systems where low-privileged or shared accounts can reach the database over the network.

8.1
group max
  • IBM Db2 11.5.0 through 11.5.9
  • IBM Db2 12.1.0 through 12.1.5
largeon the order of tens of thousands of enterprise database instances (exact count unknown; no install-base figure in the data)
CVE-2026-82107
Improper Authentication in IBM DataStage on Cloud Pak for Data 5.4.0.0

IBM DataStage running on Cloud Pak for Data version 5.4.0.0 contains an improper authentication flaw (CWE-287) rated critical with a CVSS 3.1 score of 9.6. A remote attacker who already possesses valid low-privilege credentials can trigger the flaw over the network with no user interaction, exploiting a scope change to reach resources beyond the component's normal security boundary. Successful exploitation allows the attacker to obtain sensitive information and bypass security restrictions, causing high impact to both confidentiality and integrity, though availability is not affected. Organizations running self-managed IBM DataStage 5.4.0.0 on Cloud Pak for Data deployments are the affected population. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

Do: Upgrade IBM DataStage on Cloud Pak for Data 5.4.0.0 to the fixed release specified in IBM's security bulletin as soon as it is available, and verify any interim fixes IBM publishes. Restrict network access to DataStage service endpoints to trusted users and networks, and apply least-privilege role assignments since exploitation requires only low-privilege authenticated access. Review authentication and audit logs for anomalous authenticated activity and unexpected access to sensitive data.

9.6
group max
  • IBM DataStage on Cloud Pak for Data 5.4.0.0
nichelikely hundreds to low thousands of enterprise deployments worldwide (order of magnitude, estimated)
CVE-2026-78573
Default Credentials Enable Remote Admin Takeover of IBM ContextForge MCP Gateway

IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 ship with default administrative credentials that are not forced to be changed. A remote attacker who can reach the gateway's management interface over the network can authenticate with these default credentials without any user interaction or prior privileges, gaining full administrative control of the gateway. Because the product brokers Model Context Protocol traffic between AI agents and backend tools/services, an attacker with admin access could reconfigure routing, access downstream connection details and credentials, and tamper with tool invocations. The issue carries a critical CVSS 3.1 score of 9.8, but there is no known public proof of concept and no evidence of exploitation in the wild to date.

Do: Upgrade ContextForge MCP Gateway to the latest release from IBM (anything after 1.0.7, per IBM's advisory) and immediately replace the default administrative credentials if an upgrade cannot be applied right away. Restrict network access to the gateway's admin interface (VPN, allowlist, or internal-only placement) and verify no unauthenticated-origin admin logins appear in gateway logs. Because admin access can expose downstream tool connections, rotate any API keys, tokens, or service credentials configured on affected gateways.

9.8
  • IBM ContextForge MCP Gateway 1.0.0 through 1.0.7
nichelikely hundreds to low thousands of enterprise deployments
CVE-2026-75624
Incorrect authorization security bypass in IBM App Connect Enterprise

IBM App Connect Enterprise, an enterprise integration and messaging middleware product, is affected by an incorrect authorization flaw (CWE-863) in versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.27. The issue can be triggered remotely by any authenticated user who sends a request to functionality where the product fails to correctly enforce its authorization checks, with no user interaction or special conditions required (CVSS AV:N/AC:L/PR:L/UI:N). An attacker who successfully exploits it can bypass security restrictions and gain unauthorized access to protected operations and data, with IBM scoring the potential impact as high on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). All customers running the affected version ranges of App Connect Enterprise are exposed to risk, though exploitation requires a valid account on the system. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and there are no reports of exploitation in the wild.

Do: Check the IBM PSIRT advisory for CVE-2026-75624 and upgrade App Connect Enterprise to the fixed fix-pack/release levels for the 12.x and 13.x streams (any release beyond the listed ranges per IBM's guidance). Until patched, limit network reachability of ACE nodes, review and tighten authenticated user accounts and role/permission assignments that could be abused by the authorization bypass, and monitor logs for authenticated users accessing resources outside their normal scope.

8.8
  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1
  • IBM App Connect Enterprise 12.0.1.0 through 12.0.12.27
moderate≈ low thousands of enterprise deployments (estimate; no public install counts)
CVE-2026-9327
+4 in the same advisory: …9336 …9176 …9667 …9338
Improper Privilege Management in IBM WebSphere Application Server 8.5 and 9.0

IBM WebSphere Application Server 8.5 and 9.0 suffer from an improper privilege management flaw (CWE-269) in which an authenticated user holding a low-privilege administrative role can modify the server's security configuration. The flaw is triggered through normal administrative access to the WebSphere administrative console or related admin interfaces, after valid authentication. A successful attacker can abuse this to expose sensitive information or cause denial of service, reflected in the CVSS 3.1 base score of 8.1 (high) with high confidentiality and availability impact. Any deployment of WebSphere Application Server 8.5 or 9.0 that grants administrative roles beyond fully trusted operators is affected. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

Do: Apply IBM's fix for this vulnerability (latest fix pack/interim fix per the IBM security bulletin) to all WebSphere Application Server 8.5 and 9.0 deployments. Restrict administrative console access to trusted networks and limit assignment of low-privilege administrative roles to only necessary users. Audit existing admin role assignments and review security configuration change logs for unauthorized modifications.

8.1
group max
  • IBM WebSphere Application Server 9.0, 8.5
moderate≈1,000s of internet-exposed admin endpoints; total enterprise install base likely in the tens of thousands (estimate)
CVE-2026-18486
+1 in the same advisory: …18489
Improperly Validated jq Filters Leak Credentials in IBM ContextForge MCP Gateway

IBM ContextForge MCP Gateway (MCP Context Forge) versions through v1.0.7 do not properly validate user-supplied jq filter expressions used to shape and transform JSON payloads passing through the gateway. A remote attacker who holds any low-privileged authenticated account can submit a crafted jq filter via the gateway's API, and the improperly validated filter is then processed in a way that reaches sensitive gateway data. This lets the attacker extract credentials and secrets held by or accessible to the gateway and use them to escalate privileges to higher-level access. Any deployment running ContextForge MCP Gateway v1.0.7 or earlier is affected, especially deployments with untrusted or broadly shared user accounts. No public proof-of-concept or in-the-wild exploitation is known; EPSS estimates a roughly 0.3% probability of exploitation within 30 days and the flaw is not in CISA's KEV catalog.

Do: Upgrade to the latest ContextForge MCP Gateway release (any version above v1.0.7) as soon as practical. Until then, limit gateway accounts to trusted users, restrict who can supply or configure jq filters, and keep the gateway off publicly reachable networks. If compromise is suspected, rotate the credentials, API keys, and secrets stored in or accessible through the gateway.

8.8
group max
<1%
  • IBM ContextForge MCP Gateway (MCP Context Forge) <= v1.0.7
nichelikely low hundreds to a few thousand deployments worldwide; no public exposure counts available
CVE-2026-18221
Improper Authentication in IBM i 7.3–7.6 Allows Unauthorized Remote Access

IBM i releases 7.3, 7.4, 7.5, and 7.6 fail to properly validate client-supplied authentication parameters (CWE-287), allowing a remote attacker to gain unauthorized access to the system. The flaw is triggered over the network by sending crafted authentication parameters to an affected IBM i service, with no privileges or user interaction required per the CVSS vector. An attacker who successfully bypasses authentication gains unauthorized access with potentially high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.8, critical). All organizations running IBM i on releases 7.3 through 7.6 are potentially affected, particularly where those systems are reachable from untrusted networks. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is known.

Do: Deploy the IBM-provided fixes/PTFs for this vulnerability on IBM i 7.3, 7.4, 7.5, and 7.6 as published in IBM's security bulletin. In the interim, verify whether the affected IBM i systems accept authentication traffic from untrusted networks and restrict access with firewalls or network segmentation. Since no exploit is publicly known, prioritize internet-facing and partner-facing IBM i systems for remediation first.

9.8
group max
<1%
  • IBM i 7.3, 7.4, 7.5, 7.6
large≈10,000–100,000 systems (est. ~100k+ IBM i installed base, subset network-reachable)
CVE-2026-17483
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.

NVD description · AI analysis pending
3.3<1%
  • ibm db2 mirror for i
CVE-2026-17444
+3 in the same advisory: …17443 …17440 …17442
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a r

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

NVD description · AI analysis pending
6.5
group max
<1%
  • ibm app connect enterprise
  • ibm integration bus for z\/os