Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-12118: IBM webMethods Integration: Unauthenticated Code Execution
CVE-2026-12118 · published 1 month ago
Summary
IBM webMethods Integration software on-premises versions 10.15 and 10.11 allow an attacker to run malicious code without a password. This could lead to unauthorized access and data breaches. It's recommended to update to the latest version and apply security patches to prevent exploitation.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | webmethods integration (on prem) | 10.15, 10.11 |
Original advisory text
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
References
- https://www.ibm.com/support/pages/node/7278857 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published30 Jul 2026
Updated27 Sep 2026
First seen30 Jul 2026
Track software like this
Free during beta