IBM vendor intelligence
IBM Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting IBM products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 12
- Known exploited vulnerabilities affecting IBM products
- In CISA KEV
- 8
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- IBM KEV with sensor-observed exploitation activity
The catalog gap matters for IBM exposure
Four of the twelve exploited IBM CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-third of this vendor portfolio.
- 67%
- Covered by CISA
- 33%
- Beyond CISA
- 9
- Product families
Attested IBM CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation |
Langflow OSS | Confirmed | In CISA | 04 Aug 2026 |
|
CVE-2020-4463
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote... |
Maximo Asset Management | High | Beyond CISA | 31 Aug 2025 |
|
CVE-2024-22319
IBM Operational Decision Manager JDNI injection |
Operational Decision Manager | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2019-4716
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and... |
Planning Analytics | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4428
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4427
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-4430
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker... |
Data Risk Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow... |
WebSphere | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2013-3993
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted... |
InfoSphere BigInsights | Confirmed | In CISA | 25 May 2022 |
|
CVE-2022-47986
IBM Aspera Faspex code execution |
Aspera Faspex | Confirmed | In CISA | 21 Feb 2023 |
|
CVE-2024-22320
IBM Operational Decision Manager code execution |
Operational Decision Manager | High | Beyond CISA | 02 Feb 2024 |
|
CVE-2019-4061
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed... |
BigFix Platform | High | Beyond CISA | 27 Feb 2019 |
No IBM CVEs match this search or filter.
Showing 12 of 12 IBM known exploited vulnerabilities.
Recurring weakness patterns
Deserialization, limitation, and control account for seven mapped occurrences across this IBM KEV portfolio.
CWE-502
Deserialization of Untrusted Data
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-611
Improper Restriction of XML External Entity Reference
CWE-287
Improper Authentication
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.