Serial Number: AV26-770
Date: August 4, 2026
As of July 30, 2026, IBM is affected by vulnerabilities in the following products:
- App Connect Enterprise
- Prior to or equal to 12.0.12.27
- Prior to or equal to 13.0.7.2
- DataPower Gateway 10.5.0
- Prior to or equal to 10.5.0.21
- DataPower Gateway 10.6.0
- Prior to or equal to 10.6.0.9
- DataPower Gateway 10.6CD
- Prior to or equal to 10.6.6
- DataPower Gateway 11.0.0
- Prior to or equal to 11.0.0.1
- Db2
- Prior to or equal to 11.5.9
- Prior to or equal to 12.1.4
- Engineering Requirements Management DOORS and DOORS Web Access
- Prior to or equal to 9.6.1.13
- Prior to or equal to 9.7.2.11
- Enterprise Build of Quarkus
- Prior to or equal to 3.27.4.SP2
- Prior to or equal to 3.33.2.SP2
- HMC V10.3.1050.0
- Prior to or equal to 10.3.1064.0
- HMC V11.1.1110.0
- Prior to or equal to 11.1.1112.0
- Langflow OSS
- Prior to or equal to 1.10.0
- Prior to or equal to 1.10.1
- Prior to or equal to 1.8.4
- Operations Analytics - Log Analysis
- 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3
- 1.3.6.0, 1.3.6.1
- 1.3.7.0, 1.3.7.1, 1.3.7.2
- 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4
- Planning Analytics Local
- Prior to or equal to 2.1.21
- PowerVM Hypervisor
- Prior to or equal to FW1060.71
- Prior to or equal to FW1110.20
- Prior to or equal to FW950.H1
- Security Verify Access
- Prior to or equal to 10.0.9.1
- Security Verify Access Container
- Prior to or equal to 10.0.9.1
- UCD - IBM DevOps Deploy
- Prior to or equal to 8.0.1.13
- Prior to or equal to 8.1.2.6
- Prior to or equal to 8.2.1.0
- UCD - IBM UrbanCode Deploy
- Prior to or equal to 7.2.3.23
- Prior to or equal to 7.3.2.18
- Verify Identity Access
- Prior to or equal to 11.0.2
- Verify Identity Access Container
- Prior to or equal to 11.0.2
- WebSphere Application Server
- 8.5
- 9.0
- WebSphere Application Server - Liberty
- Prior to or equal to 26.0.0.7
- webMethods Integration (on prem)
- 10.15, 10.11
The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.
On August 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9198 to their Known Exploited Vulnerabilities (KEV) Database.