Vendor
IBM
As of , 8 IBM vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-9198.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-9198Code Injection | IBM Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.29 | ||
| 2 | CVE-2015-7450Code Injection. | IBM WebSphere Application Server and Server Hypervisor Edition | Patch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 3 | CVE-2019-4716Remote Code Execution | IBM Planning Analytics | Patch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry | 0.86 | ||
| 4 | CVE-2020-4427Security Bypass | IBM Data Risk Manager | Patch this weekMetasploit module; EPSS 0.70 | 0.70 | ||
| 5 | CVE-2020-4428Remote Code Execution | IBM Data Risk Manager | Patch this weekMetasploit module; EPSS 0.62 | 0.62 | ||
| 6 | CVE-2022-47986Code Execution | IBM Aspera Faspex | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 7 | CVE-2020-4430Directory Traversal | IBM Data Risk Manager | Patch this weekEPSS 0.69 | 0.69 | ||
| 8 | CVE-2013-3993Invalid Input | IBM InfoSphere BigInsights | Patch this weekRansomware use | 0.05 |
Products
- Data Risk Manager3 entries
- Aspera Faspex1 entry
- InfoSphere BigInsights1 entry
- Langflow1 entry
- Planning Analytics1 entry
- WebSphere Application Server and Server Hypervisor Edition1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 4 |
| 2022 | 2 |
| 2023 | 1 |
| 2024 | none |
| 2025 | none |
| 2026 | 1 |