Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2782+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
16 articles

#IBM

All CosmicBytez Labs articles tagged #IBM, across news, security advisories, how-to guides, and projects.

  • SecuritySep 5, 2026

    CVE-2026-81832: XXE Flaw in IBM App Connect Enterprise SAP Adapter

    A high-severity XXE vulnerability in IBM App Connect Enterprise's SAP Adapter lets low-privileged users exfiltrate confidential data via crafted XML.

  • SecurityAug 29, 2026

    Critical Session Hijack Flaw in IBM Administration Runtime Expert for i

    CVE-2026-18527 (CVSS 9.9) lets unauthenticated attackers hijack another user's session in IBM ARE for i's legacy GUI, gaining elevated privileges.

  • SecurityAug 29, 2026

    IBM Concert SQL Injection Flaw Allows Unauthenticated Database Compromise

    CVE-2026-3627 (CVSS 9.1) lets remote attackers run arbitrary SQL against IBM Concert 1.0.0-2.3.1 with no authentication, exposing the backend DB.

  • SecurityAug 29, 2026

    Critical RCE in IBM Langflow OSS via Unauthenticated A2A Endpoint

    CVE-2026-19286 (CVSS 9.8) lets remote attackers execute arbitrary code on Langflow OSS 1.0.0-1.11.1 through the public A2A endpoint, no auth needed.

  • SecurityAug 29, 2026

    IBM Langflow OSS Flaw Lets Authenticated Users Escalate to Full RCE

    CVE-2026-19295 (CVSS 9.9) lets an authenticated Langflow user run arbitrary OS commands by crafting a flow, bypassing the custom-component lockdown.

  • SecurityAug 21, 2026

    CVE-2026-16926: IBM AIX & PowerVM VIOS Critical Arbitrary File Overwrite

    IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 have a critical flaw allowing remote attackers to overwrite arbitrary files. CVSS 9.1. Patch via IBM Fix Central.

  • SecurityAug 14, 2026

    CVE-2026-17482: Critical RCE in IBM Documentation Offline

    IBM Documentation Offline versions 1.0.0–1.4.1 contain a critical path traversal flaw allowing remote code execution with a CVSS score of 9.8.

  • SecurityJul 31, 2026

    CVE-2026-11707: IBM WebSphere Application Server Admin Console XSS (CVSS 9.3)

    Critical cross-site scripting vulnerability in IBM WebSphere Application Server's administrative console login page enables unauthenticated remote attackers to hijack admin sessions.

  • SecurityJul 31, 2026

    CVE-2026-15435: IBM App Connect Enterprise Path Traversal — Arbitrary File Write (CVSS 9.8)

    Critical path traversal vulnerability in IBM App Connect Enterprise allows unauthenticated remote attackers to write arbitrary files on the system using dot-dot sequences in crafted URLs.

  • SecurityJul 29, 2026

    CVE-2026-14446: IBM WebSphere Admin Console Privilege Escalation

    A critical broken access control flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows attackers to escalate privileges via the administrative console.

  • SecurityJul 29, 2026

    CVE-2026-14512: IBM WebSphere Pre-Auth Deserialization Allows RCE

    A critical pre-authentication unsafe deserialization flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows remote attackers to bypass authentication or execute arbitrary code.

  • SecurityJul 29, 2026

    CVE-2026-14958: IBM Aspera Faspex 5 Shell Injection Enables RCE

    A critical unquoted shell interpolation vulnerability (CVSS 9.1) in IBM Aspera Faspex 5 (versions 5.0.0–5.0.15.4) allows authenticated remote attackers to execute arbitrary code.

  • SecurityJul 18, 2026

    CVE-2026-13446: IBM Langflow Hardcoded Credentials (CVSS 9.8)

    IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hardcoded credentials used for inbound authentication and internal encryption, allowing...

  • NewsJul 2, 2026

    Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

    IBM and Red Hat announced Project Lightwell — a $5 billion commitment to secure open-source supply chains using Anthropic's Mythos AI model, which found...

  • SecurityJul 1, 2026

    CVE-2025-36359: IBM DevOps Session Hijacking Vulnerability (CVSS 8.1)

    IBM DevOps Automation and IBM DevOps Loop fail to invalidate session IDs after expiration, allowing authenticated attackers to impersonate other users via...

  • NewsMay 28, 2026

    IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under "Project Lightwell"

    IBM and Red Hat unveil Project Lightwell, a $5B commitment to securing open-source supply chains by fixing vulnerabilities without breaking production.