IBM security advisory (AV26-1022)
Canada's Cyber Centre says IBM DataPower Gateway and Langflow OSS need patches, including XSS CVE-2026-14990.
On October 8, 2026, the Canadian Centre for Cyber Security issued advisory AV26-1022. IBM DataPower Gateway releases through 10.5.0.22, 10.6.0.10, 10.6.6, and 11.0.0.2 are affected, including cross-site scripting tracked as CVE-2026-14990, plus other unspecified CVEs. Langflow OSS versions 1.0.0 through 1.12.2 are affected by multiple vulnerabilities. The centre urges administrators to review IBM’s bulletins and apply updates. The advisory does not report exploitation in the wild.
- Advisory AV26-1022 covers IBM DataPower Gateway and Langflow OSS.
- CVE-2026-14990 is a cross-site scripting flaw in DataPower Gateway.
- Affected DataPower branches include 10.5, 10.6, 10.6CD, and 11.0.
- Langflow OSS 1.0.0 through 1.12.2 has multiple vulnerabilities.
- No in-the-wild exploitation is stated; administrators should apply updates.
Vulnerabilities mentionedAll →
- CVE-2026-149909.3—Unauthenticated XSS in IBM DataPower Gateway Web UIpublished · IBM DataPower Gateway
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-14990 | Unauthenticated XSS in IBM DataPower Gateway Web UI IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 has a cross-site scripting flaw (CWE-79) in the Web UI. An unauthenticated attacker can embed arbitrary JavaScript that runs in a victim's browser when they use the UI, changing how the interface behaves. In a trusted session that script can be used to disclose credentials, with high confidentiality and integrity impact and no availability impact (CVSS 3.1 9.3). Only those DataPower Gateway releases are named as affected. It is not listed in CISA KEV and no public proof-of-concept is known. Do: Upgrade IBM DataPower Gateway to a release newer than 10.6.0.10 as directed by IBM's security bulletin, and do not treat 10.6.0.0–10.6.0.10 as safe. Until patched, restrict the Web UI to trusted management networks, require a VPN or jump host, and review admin sessions and credential use for unexpected activity. |
Full article118 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1022
Date: October 8, 2026
As of October 8, 2026, IBM is affected by vulnerabilities in the following products:
- IBM DataPower Gateway 10.5.0
- Prior to or equal to 10.5.0.22
- IBM DataPower Gateway 10.6.0
- Prior to or equal to 10.6.0.10
- IBM DataPower Gateway 10.6CD
- Prior to or equal to 10.6.6
- IBM DataPower Gateway 11.0.0
- Prior to or equal to 11.0.0.2
- Langflow OSS
- Version 1.0.0 to 1.12.2
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-1022