Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-18163: IBM Financial Transaction Manager on OpenShift can run attacker code

CVE-2026-18163 · published 6 days ago
Summary

IBM Financial Transaction Manager running on RedHat OpenShift can be tricked into executing code from an untrusted source. A remote attacker could take control of the system and access sensitive transaction data. Install IBM's latest security update and ensure only trusted data is processed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm financial transaction manager (ftm) for redhat openshift <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064
Original advisory text
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Sep 2026
Updated29 Sep 2026
First seen22 Sep 2026
Sources
CVE-2026-18163 · MITRE
Track software like this
Free during beta