Canada urges patches for IBM and Langflow flaws
Canada’s Cyber Centre urged patches for IBM DataStage, Guardium, IBM i, DataPower, and Langflow, citing two 2026 CVEs.
The Canadian Centre for Cyber Security published advisory AV26-997 on October 5, 2026, stating that IBM products were affected as of September 29, 2026. It covers DataStage on Cloud Pak for Data 5.4.0.0, Guardium Data Protection 12.2, and IBM i 7.3, 7.4, 7.5, and 7.6, including incorrect permission assignment CVE-2026-84414 in IBM i Network Authentication Service. On October 8, 2026, advisory AV26-1022 said DataPower Gateway releases through 10.5.0.22, 10.6.0.10, 10.6.6, and 11.0.0.2 are affected, including cross-site scripting CVE-2026-14990 and other unspecified CVEs; a point list also names branches 10.5, 10.6, 10.6CD, and 11.0. The same notice says Langflow OSS 1.0.0 through 1.12.2 has multiple vulnerabilities. Administrators are urged to review IBM’s bulletins and apply updates, and neither advisory reports exploitation in the wild. The two notices name different products and CVE identifiers and do not contradict each other.
- Canadian Centre for Cyber Security advisory AV26-997, dated October 5, 2026, says IBM products were affected as of September 29, 2026.
- AV26-997 covers DataStage on Cloud Pak for Data 5.4.0.0, Guardium Data Protection 12.2, and IBM i 7.3, 7.4, 7.5, and 7.6.
- CVE-2026-84414 is an incorrect permission assignment in IBM i Network Authentication Service.
- Advisory AV26-1022, dated October 8, 2026, covers DataPower Gateway releases through 10.5.0.22, 10.6.0.10, 10.6.6, and 11.0.0.2, including XSS CVE-2026-14990 and other unspecified CVEs.
- The same notice lists affected DataPower branches as 10.5, 10.6, 10.6CD, and 11.0.
- Langflow OSS 1.0.0 through 1.12.2 is affected by multiple vulnerabilities.
- Neither advisory reports in-the-wild exploitation; administrators are told to review IBM bulletins and apply updates.
Coverage timelineoldest first · each row is one article
- · 3d agoIBM security advisory (AV26-997)
Canadian Centre for Cyber Security· 34
Canada’s Cyber Centre urges patches for IBM DataStage, Guardium, and IBM i, including CVE-2026-84414.
- · 8h agoIBM security advisory (AV26-1022)
Canadian Centre for Cyber Security· 36
Canada's Cyber Centre says IBM DataPower Gateway and Langflow OSS need patches, including XSS CVE-2026-14990.
Vulnerabilities in this storyAll →
- CVE-2026-149909.3—Unauthenticated XSS in IBM DataPower Gateway Web UIpublished · IBM DataPower Gateway
- CVE-2026-844147.8—Local arbitrary file ownership change in IBM ipublished · IBM i
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|