T
Threats
IBM Critical Vulnerabilities
Overview
IBM has disclosed five critical vulnerabilities across several software and infrastructure products. Four issues may be exploited remotely without authentication. The Langflow issue requires an attacker to reach a permitted run path that invokes the affected Python component, while the Tivoli-related WebSphere cross-site scripting issue requires user interaction.
CVE: CVE-2026-13435, CVE-2026-15435, CVE-2026-12118, CVE-2026-12943, CVE-2026-11707
Overall severity: Critical
Date: 31 July 2026
Affected Versions
IBM Langflow OSS
Affected: Versions 1.0.0 through 1.10.1
Fixed: Version 1.10.2
Source: IBM Langflow Python Interpreter sandbox bypass bulletin
IBM App Connect Enterprise
Affected: Versions 13.0.1.0 through 13.0.7.2
Fixed: Version 13.0.8.0
Source: IBM App Connect Enterprise arbitrary file write bulletin
Affected: Versions 12.0.1.0 through 12.0.12.27
Fixed: Version 12.0.12.28
Source: IBM App Connect Enterprise arbitrary file write bulletin
IBM webMethods Integration Server
Affected: On-premises versions 10.11 and 10.15 when the WmServiceMock package is present
Fixed: IBM states that no product patch or software update is required. Remove WmServiceMock from every production or internet-facing Integration Server node, then restart the server.
IBM Power Hardware Management Console
Affected: V10.3.1050.0 through V10.3.1064.0
Fixed: V10.3.1064.1 x86 with MF71762, or V10.3.1064.1 ppc with MF71763
Affected: V11.1.1110.0 through V11.1.1112.0
Fixed: V11.1.1112.1 x86 with MF71764, or V11.1.1112.1 ppc with MF71765
IBM Tivoli System Automation Application Manager and WebSphere Application Server
Affected: Tivoli System Automation Application Manager 4.1 when shipped with WebSphere Application Server 8.5 or 9.0. The supporting WebSphere bulletin identifies affected traditional WebSphere ranges as 8.5.0.0 through 8.5.5.29 and 9.0.0.0 through 9.0.5.28.
Fixed: Apply the interim fix for APAR PH71757 at the minimum fix pack level required by IBM. Alternatively, apply WebSphere Fix Pack 8.5.5.30 or later, or 9.0.5.29 or later, when available for the relevant branch.
Source: IBM Tivoli System Automation Application Manager bulletin
Vulnerability Breakdown
CVE-2026-13435 – Python Interpreter sandbox bypass
Severity: Critical
CVSS: 9.9
Description: Improper input validation in the Langflow OSS PythonREPL sandbox can allow supplied code to bypass validation. An attacker able to provide input to a deployed flow, agent or permitted run path that invokes the affected Python component may access sensitive server-process and in-memory values.
Impact: Exposure of provider API keys, database credentials and cryptographic key material. Under the default HS256 JWT configuration, exposed key material may enable token forgery for a known user identifier and decryption of stored credentials.
Conditions: Network access and low privileges are reflected in IBM’s CVSS vector. The affected Python component must be reachable through a deployed flow, agent or permitted run path.
CVE-2026-15435 – Path traversal and arbitrary file write
Severity: Critical
CVSS: 9.8
Description: IBM App Connect Enterprise does not adequately restrict pathnames. A remote attacker can send a specially crafted URL containing directory traversal sequences to write arbitrary files.
Impact: Compromise of confidentiality, integrity and availability through unauthorised file placement or modification.
Conditions: Network access is required. IBM’s CVSS vector indicates no privileges or user interaction are required.
CVE-2026-12118 – Deserialisation of untrusted data
Severity: Critical
CVSS: 9.8
Description: The WmServiceMock development and testing package bundled with IBM webMethods Integration Server can deserialize untrusted data. If the package is deployed on an exposed server, an unauthenticated remote attacker may execute arbitrary code.
Impact: Arbitrary code execution in the Integration Server environment, with potential system and data compromise.
Conditions: WmServiceMock must be installed and reachable. IBM states that it should not be deployed on production or internet-facing systems.
CVE-2026-12943 – OS command injection
Severity: Critical
CVSS: 9.8
Description: Improper validation of user-supplied input in IBM Power management systems can allow an unauthenticated attacker to execute arbitrary commands with elevated privileges.
Impact: Full compromise of confidentiality, integrity and availability on the affected management system.
Conditions: Network access is required. IBM’s CVSS vector indicates no privileges or user interaction are required.
CVE-2026-11707 – Administrative console login page cross-site scripting
Severity: Critical
CVSS: 9.3
Description: IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager is vulnerable to cross-site scripting in the administrative console login page.
Impact: Execution of attacker-controlled script in a user’s browser, with high potential impact to confidentiality and integrity.
Conditions: The vulnerable administrative console must be reachable and a user must interact with malicious content. IBM’s CVSS vector indicates no privileges are required.
Mitigation
Upgrade Langflow OSS to version 1.10.2.
Upgrade IBM App Connect Enterprise 13.x to 13.0.8.0, or 12.x to 12.0.12.28.
Remove WmServiceMock from every production and internet-facing IBM webMethods Integration Server node, then restart Integration Server.
If WmServiceMock must remain in development or testing, isolate the environment and verify authentication is enforced on all Integration Server ports.
Apply the IBM Power HMC fixes for the affected architecture and branch.
Apply the WebSphere interim fix for APAR PH71757, or the applicable fixed WebSphere fix pack when available.
Prioritise internet-facing and management-plane systems, then confirm remediation through version and configuration checks.
Summary for IT Teams
Products: IBM App Connect Enterprise, IBM webMethods Integration Server, IBM Power HMC, IBM Langflow OSS, IBM Tivoli System Automation Application Manager and IBM WebSphere Application Server
Threat level: Critical, maximum CVSS 9.9
Action required: Identify affected versions, upgrade App Connect Enterprise and Langflow, remove WmServiceMock from production, apply Power HMC fixes and remediate WebSphere with APAR PH71757 or the applicable fixed fix pack.

