IBM disclosed numerous vulnerabilities in Financial Transaction Manager (FTM) for Red Hat OpenShift, affecting releases 4.0.6.0 through 4.0.10.0, including specified 4.0.6.0 iFix6 builds. The flaws include unauthenticated remote code execution, code and SQL/ESQL injection, insecure deserialization, authentication and authorization failures, stored cross-site scripting, XXE, buffer overflows, hard-coded credentials and cryptographic keys, privilege-management defects, and transaction-payment manipulation. The highest-rated issues include CVE-2026-18169 (CVSS 9.9), CVE-2026-18162 and CVE-2026-18163 (CVSS 9.8), CVE-2026-18872 (CVSS 9.3), and CVE-2026-17635 and CVE-2026-17645 (CVSS 9.1).
Notable exposure includes unauthenticated remote code execution through user-controlled input passed to the JavaScript Function constructor in CVE-2026-18162, unauthenticated SQL/ESQL command execution in CVE-2026-18137, and unauthorized remote actions caused by improper authentication in CVE-2026-18074. Other defects could enable code execution, disclosure or modification of sensitive transaction data, and privilege escalation. IBM advises affected organizations to upgrade to FTM 4.0.11.0; no alternative workaround or mitigation was provided. Administrators should prioritize patching internet-accessible and transaction-processing deployments, review access controls, and assess for suspicious activity associated with exposed FTM instances.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
IBM PSIRT received or published CVE records for multiple FTM for Red Hat OpenShift flaws, including critical CVE-2026-18169 symbolic-link validation and CVE-2026-18162 code-injection RCE issues, plus SQL/ESQL injection, XSS, deserialization, credential, authentication, privilege-management, XXE, buffer-overflow, and cryptographic-key weaknesses. The records describe impacts ranging from information disclosure and unauthorized actions to arbitrary code execution and elevated privileges.
The Canadian Centre for Cyber Security published advisory AV26-943 covering vulnerabilities affecting multiple IBM product lines. It directed administrators to review IBM PSIRT guidance and apply the required vendor updates.
IBM published Security Bulletin 7288641 covering numerous vulnerabilities in Financial Transaction Manager for Red Hat OpenShift versions 4.0.6.0 through 4.0.10.0. IBM advised upgrading to FTM 4.0.11.0, stating that no workaround or mitigation was available other than applying the fixed release.
Multiple IBM products were reported as affected by vulnerabilities, including CICS TX Advanced, Guardium Data Protection, IBM MQ, Sterling File Gateway, WebSphere Application Server, IBM i, Spectrum LSF, and IBM Platform RTM.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceibm.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.