Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12118: IBM webMethods Integration: Unauthenticated Code Execution

CVE-2026-12118 · published 1 month ago
Summary

IBM webMethods Integration software on-premises versions 10.15 and 10.11 allow an attacker to run malicious code without a password. This could lead to unauthorized access and data breaches. It's recommended to update to the latest version and apply security patches to prevent exploitation.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm webmethods integration (on prem) 10.15, 10.11
Original advisory text
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
References
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published30 Jul 2026
Updated27 Sep 2026
First seen30 Jul 2026
Sources
CVE-2026-12118 · MITRE
Track software like this
Free during beta