Vulnerability
Published 2026-09-28
Verified 2026-10-09

IBM DataPower Gateway: 36 CVEs fixed, including unauthenticated remote code execution (CVE-2026-16340, CVE-2026-14269) and admin access via empty LDAP passwords (CVE-2026-14502), all CVSS 9.8; upgrade to 10.5.0.23, 10.6.0.11 or 11.0.0.3

IBM's security bulletin for DataPower Gateway, first published on 28 September 2026, fixes 36 CVEs; the CVE records went public on 8 October 2026. DataPower is a security and integration gateway often placed at the network edge in front of APIs, web services and mainframe systems. Flaws rated CVSS 9.8 include CVE-2026-16340 (out-of-bounds write in the RFC 2047 encoded-word parser allowing a remote attacker to run code), CVE-2026-15762 (out-of-bounds write allowing remote code execution), CVE-2026-14269 (heap-based buffer overflow letting an unauthenticated remote attacker run code), CVE-2026-14502 (a remote attacker can gain administrative access because empty passwords are not rejected during LDAP authentication) and buffer overflows CVE-2026-14991 and CVE-2026-14992 (IBM's text for CVE-2026-14991 describes a local user). Affected: 10.5.0.0 to 10.5.0.22, 10.6.0.0 to 10.6.0.10, 10.6CD 10.6.1 to 10.6.6, and 11.0.0.0 to 11.0.0.2. IBM lists no workarounds, flags known issue DT499224, and reports no exploitation. Primary: IBM.

Product
IBM DataPower Gateway
Versions
10.5.0.0–10.5.0.22; 10.6.0.0–10.6.0.10; 10.6CD 10.6.1–10.6.6; 11.0.0.0–11.0.0.2
CVSS
(CVE-2026-16340, CVE-2026-15762, CVE-2026-14269, CVE-2026-14502, CVE-2026-14991, CVE-2026-14992)
Exploited in Australia?
unknown
Patch to
Upgrade to 10.5.0.23 (10.5.0 stream), 10.6.0.11 (10.6.0 stream) or 11.0.0.3 (10.6CD and 11.0.0 streams). There is no workaround; until upgraded, check LDAP authentication settings, restrict access to the management interfaces, and read known issue DT499224 before upgrading.

Primary: IBM — Security Bulletin: IBM DataPower Gateway multiple vulnerabilities (28 Sep 2026; CVE records published 8 Oct 2026) · CVE: CVE-2026-16340, CVE-2026-14269, CVE-2026-14502, CVE-2026-15762, CVE-2026-14991, CVE-2026-14992 · NVD — CVE-2026-16340 (CNA IBM, published 8 Oct 2026)

vulnerabilities network identity