IBM released security updates for multiple products after disclosures covering at least 21 high-severity vulnerabilities across Langflow OSS, Application Gateway Operator, QRadar, and WebSphere Application Server. The issues span remote code execution, arbitrary file read/write, information disclosure, security restriction bypass, and server-side request forgery, with national CERT and CSIRT notices urging organizations to apply IBM’s bulletins and upgrade affected deployments.
Among the disclosed flaws, CVE-2026-17624 affects IBM Langflow OSS versions 1.0.0 through 1.10.3 and allows a remote authenticated attacker to execute arbitrary code through improper validation of module imports in component generation, validation, and custom component handling. CVE-2026-17617 affects IBM Application Gateway Operator versions 22.2.0 through 26.06 and enables SSRF through insufficient validation of URLs in custom resources; additional affected products include QRadar 7.6.0.1 and earlier in the 7.6.x branch, QRadar 7.5.0 UP 15 IF05 and earlier in the 7.5.x branch, WebSphere Application Server 8.5 and 9.0, and **WebSphere Liberty Continuous Delivery`.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE history states that IBM PSIRT newly received CVE-2026-17624 on August 5, 2026. The flaw is an arbitrary code execution issue in IBM Langflow OSS affecting versions 1.0.0 through 1.10.3.
The CVE record states that IBM PSIRT newly received CVE-2026-17617 on August 5, 2026. The vulnerability is an SSRF issue in IBM Application Gateway Operator affecting versions 22.2.0 through 26.06.
IBM released security updates covering multiple vulnerabilities across Langflow OSS, Application Gateway Operator, QRadar, and WebSphere Application Server. The notice says 21 of the vulnerabilities are high severity and recommends updating affected products according to IBM security bulletins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecert.gov.py
Open sourcecert.gov.py
Open sourcecert.gov.py
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.