Vendor

IBM

As of , 8 IBM vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-9198.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-9198Code InjectionIBM LangflowPatch nowForensic triage required by CISA; Metasploit module0.29
2CVE-2015-7450Code Injection.IBM WebSphere Application Server and Server Hypervisor EditionPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
3CVE-2019-4716Remote Code ExecutionIBM Planning AnalyticsPatch this weekMetasploit module; EPSS 0.86; verified Exploit-DB entry0.86
4CVE-2020-4427Security BypassIBM Data Risk ManagerPatch this weekMetasploit module; EPSS 0.700.70
5CVE-2020-4428Remote Code ExecutionIBM Data Risk ManagerPatch this weekMetasploit module; EPSS 0.620.62
6CVE-2022-47986Code ExecutionIBM Aspera FaspexPatch this weekRansomware use; EPSS 0.990.99
7CVE-2020-4430Directory TraversalIBM Data Risk ManagerPatch this weekEPSS 0.690.69
8CVE-2013-3993Invalid InputIBM InfoSphere BigInsightsPatch this weekRansomware use0.05

Products

  • Data Risk Manager3 entries
  • Aspera Faspex1 entry
  • InfoSphere BigInsights1 entry
  • Langflow1 entry
  • Planning Analytics1 entry
  • WebSphere Application Server and Server Hypervisor Edition1 entry

Added each year

12342021: 4420212022: 2220222023: 1120232024: nonenone20242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20214
20222
20231
2024none
2025none
20261

Used in ransomware