ZeroHour

Vulnerabilities

25 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87958
+2 in the same advisory: …86093 …86087
Privileged-user denial-of-service flaw in IBM Db2 11.5 and 12.1

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a denial-of-service vulnerability (CWE-269, improper privilege management) in which a specific functionality on a Db2 server can be disabled. The flaw is triggered over the network by an authenticated user holding privileges on the Db2 server — the CVSS vector grades required privileges as low (PR:L) — and requires no user interaction, under certain conditions on the server. A successful attacker can disable that functionality, hitting availability; the 8.1 High CVSS vector also scores high integrity impact (C:N/I:H/A:H), suggesting the affected functionality can be left in a modified or disabled state. Any organization running the listed Db2 11.5.x or 12.1.x releases is potentially affected, though exploitation requires an account with privileges on the database server. There is no evidence of exploitation: the flaw is not in CISA KEV, and no public proof-of-concept is known.

Do: Check IBM's PSIRT advisory for CVE-2026-87958 to identify the fixed fix pack or interim-fix level (not specified in the available data) and plan upgrades for all 11.5.x and 12.1.x Db2 deployments. As an interim mitigation, restrict which accounts hold administration privileges on Db2 servers and audit recent configuration changes to the affected functionality. Prioritize systems where low-privileged or shared accounts can reach the database over the network.

8.1
group max
  • IBM Db2 11.5.0 through 11.5.9
  • IBM Db2 12.1.0 through 12.1.5
largeon the order of tens of thousands of enterprise database instances (exact count unknown; no install-base figure in the data)
CVE-2026-82107
Improper Authentication in IBM DataStage on Cloud Pak for Data 5.4.0.0

IBM DataStage running on Cloud Pak for Data version 5.4.0.0 contains an improper authentication flaw (CWE-287) rated critical with a CVSS 3.1 score of 9.6. A remote attacker who already possesses valid low-privilege credentials can trigger the flaw over the network with no user interaction, exploiting a scope change to reach resources beyond the component's normal security boundary. Successful exploitation allows the attacker to obtain sensitive information and bypass security restrictions, causing high impact to both confidentiality and integrity, though availability is not affected. Organizations running self-managed IBM DataStage 5.4.0.0 on Cloud Pak for Data deployments are the affected population. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

Do: Upgrade IBM DataStage on Cloud Pak for Data 5.4.0.0 to the fixed release specified in IBM's security bulletin as soon as it is available, and verify any interim fixes IBM publishes. Restrict network access to DataStage service endpoints to trusted users and networks, and apply least-privilege role assignments since exploitation requires only low-privilege authenticated access. Review authentication and audit logs for anomalous authenticated activity and unexpected access to sensitive data.

9.6
group max
  • IBM DataStage on Cloud Pak for Data 5.4.0.0
nichelikely hundreds to low thousands of enterprise deployments worldwide (order of magnitude, estimated)
CVE-2026-78573
Default Credentials Enable Remote Admin Takeover of IBM ContextForge MCP Gateway

IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 ship with default administrative credentials that are not forced to be changed. A remote attacker who can reach the gateway's management interface over the network can authenticate with these default credentials without any user interaction or prior privileges, gaining full administrative control of the gateway. Because the product brokers Model Context Protocol traffic between AI agents and backend tools/services, an attacker with admin access could reconfigure routing, access downstream connection details and credentials, and tamper with tool invocations. The issue carries a critical CVSS 3.1 score of 9.8, but there is no known public proof of concept and no evidence of exploitation in the wild to date.

Do: Upgrade ContextForge MCP Gateway to the latest release from IBM (anything after 1.0.7, per IBM's advisory) and immediately replace the default administrative credentials if an upgrade cannot be applied right away. Restrict network access to the gateway's admin interface (VPN, allowlist, or internal-only placement) and verify no unauthenticated-origin admin logins appear in gateway logs. Because admin access can expose downstream tool connections, rotate any API keys, tokens, or service credentials configured on affected gateways.

9.8
  • IBM ContextForge MCP Gateway 1.0.0 through 1.0.7
nichelikely hundreds to low thousands of enterprise deployments
CVE-2026-9327
+2 in the same advisory: …9176 …9667
Improper Privilege Management in IBM WebSphere Application Server 8.5 and 9.0

IBM WebSphere Application Server 8.5 and 9.0 suffer from an improper privilege management flaw (CWE-269) in which an authenticated user holding a low-privilege administrative role can modify the server's security configuration. The flaw is triggered through normal administrative access to the WebSphere administrative console or related admin interfaces, after valid authentication. A successful attacker can abuse this to expose sensitive information or cause denial of service, reflected in the CVSS 3.1 base score of 8.1 (high) with high confidentiality and availability impact. Any deployment of WebSphere Application Server 8.5 or 9.0 that grants administrative roles beyond fully trusted operators is affected. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

Do: Apply IBM's fix for this vulnerability (latest fix pack/interim fix per the IBM security bulletin) to all WebSphere Application Server 8.5 and 9.0 deployments. Restrict administrative console access to trusted networks and limit assignment of low-privilege administrative roles to only necessary users. Audit existing admin role assignments and review security configuration change logs for unauthorized modifications.

8.1
group max
  • IBM WebSphere Application Server 9.0, 8.5
moderate≈1,000s of internet-exposed admin endpoints; total enterprise install base likely in the tens of thousands (estimate)