IBM patches 90 CVEs across enterprise software
IBM released security updates addressing 90 vulnerabilities across multiple enterprise products including WebSphere, QRadar SIEM, Sterling B2B, and DB2, with risks including RCE and privilege escalation.
The French CERT (CERT-FR) has published an advisory covering multiple security vulnerabilities discovered in IBM enterprise products. The affected software spans IBM's core enterprise portfolio including WebSphere Application Server (versions 8.5.0, 9.0.0-9.0.5.28, and Liberty 17.x-26.x), QRadar SIEM 7.5.0, Sterling B2B Integrator and File Gateway 6.2.1, Sterling Connect:Direct components, DB2 Query Management Facility, and Tivoli Composite Application Manager.
The vulnerabilities enable multiple attack vectors including remote code execution, privilege escalation, server-side request forgery (SSRF), cross-site scripting (XSS), SQL injection, security policy bypass, and denial of service. IBM published 25 security bulletins between June 12-18, 2026, addressing 90 distinct CVE identifiers spanning from 2024 through 2026. The advisory lists CVEs ranging from CVE-2024-38820 through CVE-2026-46333.
IBM has released patches and updates for all affected products. Organizations running these IBM enterprise platforms should consult the referenced security bulletins and apply the appropriate fixes based on their deployed versions. The breadth of affected products and vulnerability types suggests this represents IBM's regular quarterly security update cycle rather than emergency patching of actively exploited flaws.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0788/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free