Changeflow GovPing Data Privacy & Cybersecurity IBM App Connect Enterprise Critical Vulnerabili...
Urgent Notice Added Final

IBM App Connect Enterprise Critical Vulnerabilities

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 26th, 2026
Detected March 28th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding critical vulnerabilities in IBM App Connect Enterprise versions prior to 11.6.0, 12.21.0, and 12.0.22. The vulnerabilities, with a CVSS base score of 9.8, could allow attackers to manipulate files, cause denial of service, execute arbitrary code, or perform cross-site scripting attacks.

What changed

CERT-Bund has released a security advisory (WID-SEC-2026-0895) detailing critical vulnerabilities affecting IBM App Connect Enterprise. The vulnerabilities, rated with a CVSS base score of 9.8, allow for remote attacks including file manipulation, denial of service, arbitrary code execution, and cross-site scripting. Affected versions include IBM App Connect Enterprise <11.6.0, <12.21.0, and LTS <12.0.22, running on Linux, UNIX, and Windows operating systems.

Organizations using vulnerable versions of IBM App Connect Enterprise must apply available mitigations immediately to address these critical security risks. Failure to do so could result in severe system compromise, including unauthorized code execution and data manipulation. The advisory indicates that mitigations are available, and users should consult IBM's security advisories for specific patching and remediation steps.

What to do next

  1. Apply available mitigations for IBM App Connect Enterprise
  2. Update to patched versions of IBM App Connect Enterprise

Source document (simplified)

[WID-SEC-2026-0895] IBM App Connect Enterprise: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 26.03.2026 Stand 27.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

IBM App Connect Enterprise kombiniert die branchenbewährten Technologien des IBM Integration Bus mit Cloud-nativen Technologien.

Produkte

26.03.2026
- IBM App Connect Enterprise <11.6.0

  • IBM App Connect Enterprise <12.21.0

  • IBM App Connect Enterprise LTS <12.0.22

Angriff

Angriff

Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, und um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 26th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0895

Who this affects

Applies to
Manufacturers
Industry sector
3254 Pharmaceutical Manufacturing
Activity scope
Vulnerability Management System Security
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Product Security Vulnerability Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.