IBM released security updates for critical and high-severity vulnerabilities affecting Langflow OSS, IBM MQ, and IBM Sterling File Gateway. Langflow OSS versions 1.0.0 through 1.10.0 are vulnerable to CVE-2026-12944 (CVSS 9.6), where an incomplete dangerous-import blocklist can let authenticated users submit components that make network connections during server-side validation. Exploitation could enable SSRF against cloud metadata services, reverse shells, file exfiltration, access to internal Docker services, and code execution as root; IBM recommends upgrading to Langflow OSS 1.10.1. IBM MQ's JMS client is affected by CVE-2026-13293 (CVSS 8.8), a Java deserialization allowlist-bypass flaw that can allow an authenticated remote attacker to execute arbitrary code when a target consumes JMS ObjectMessages.
IBM also addressed nine vulnerabilities across MQ middleware releases, including critical CVE-2026-11381 and high-severity CVE-2026-11375 and CVE-2026-11378, which may permit authenticated remote code execution, as well as CVE-2026-11726, which may expose protected information. Updates are available for supported IBM MQ 9.1 through 9.4 LTS releases; Continuous Delivery and IBM MQ 10.0 users should move to 10.0.0.5. Separately, CVE-2026-19290 (CVSS 7.5) allows unauthenticated remote access to sensitive information in Sterling File Gateway versions 6.2.0.0–6.2.0.6_1, 6.2.1.0–6.2.1.2, and 6.2.2.0–6.2.2.1; customers should apply APAR IT49875 by upgrading to 6.2.0.6_2, 6.2.1.2_1, or 6.2.2.1_1. No workarounds were provided, and IBM had not reported active exploitation of the MQ flaws.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published AV26-922, advising administrators to review IBM advisories and apply updates for affected Langflow OSS, IBM MQ, and IBM Sterling File Gateway releases. The advisory highlighted CVE-2026-13293 in IBM MQ and CVE-2026-19290 in Sterling File Gateway.
IBM disclosed CVE-2026-13293, a CVSS 8.8 Java deserialization allowlist-bypass flaw in the IBM MQ JMS client. A remote authenticated attacker could execute arbitrary code on systems consuming JMS ObjectMessages; IBM issued cumulative security updates for supported LTS releases and directed CD and 10.0 users to upgrade to 10.0.0.5.
IBM published a bulletin for CVE-2026-19290, a CVSS 7.5 improper-access-control vulnerability in Sterling File Gateway that could let an unauthenticated remote attacker obtain sensitive information. IBM provided APAR IT49875 and fixed releases for affected 6.2.0.x, 6.2.1.x, and 6.2.2.x versions.
IBM disclosed CVE-2026-12944 in Langflow OSS, affecting versions 1.0.0 through 1.10.0. The incomplete security-scanner blocklist could allow authenticated users to trigger server-side network actions and potentially execute Python code as root; IBM recommended upgrading to version 1.10.1.
IBM MQ security updates were reported to remediate nine vulnerabilities, including critical CVE-2026-11381 and additional high-severity flaws CVE-2026-11375, CVE-2026-11378, and CVE-2026-11726. Fixes were available in MQ 9.1.0.38, 9.2.0.44, 9.3.0.42, and 9.4.0.26 LTS releases, while CD and 10.0.0.0 users were directed to upgrade to 10.0.0.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceibm.com
Open sourceibm.com
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.