IBMCVE-2026-12118
IBM webMethods Integration (on prem): remote code execution
Critical9.8CVE-2026-12118 · Published Jul 30, 2026 · updated Aug 10, 2026
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| webMethods Integration (on prem) Product | <= 10.15, 10.11 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-502
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 30 | IBM WebSphere Application Server: remote code execution | High8.5 | No fix yet |
| Jul 30 | IBM Langflow OSS: code injection | Critical9.9 | No fix yet |
| Jul 30 | UCD - IBM: information disclosure | Medium4.3 | No fix yet |
| Jul 30 | IBM Langflow OSS: improper input validation | Critical9.9 | No fix yet |
| Jul 30 | IBM Langflow OSS: attacker could access another user's private vector | High8.1 | No fix yet |
| Jul 30 | IBM Langflow OSS: path traversal | High7.5 | No fix yet |