13 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-12666 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-16432 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacke | HIGH | 7.7 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-13107 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to X | HIGH | 7.1 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-13275 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 17%ile | NVD | 2026-09-14 |
| CVE-2026-13285 | IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could | HIGH | 7.1 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-13287 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-12756 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta | HIGH | 7.1 | 42%ile | NVD | 2026-09-14 |
| CVE-2026-91197 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFa | HIGH | 7.1 | 19%ile | NVD | 2026-09-14 |
| CVE-2026-12667 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-12752 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta | HIGH | 7.1 | 42%ile | NVD | 2026-09-15 |
| CVE-2026-13265 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | MEDIUM | 6.8 | 13%ile | NVD | 2026-09-14 |
| CVE-2026-76427 | A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read | MEDIUM | 4.9 | 27%ile | NVD | 2026-09-16 |
| CVE-2026-76446 | A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific& | MEDIUM | 4.9 | 23%ile | NVD | 2026-09-16 |