IBM DataPower Gateway: 36 CVEs fixed, including unauthenticated remote code execution (CVE-2026-16340, CVE-2026-14269) and admin access via empty LDAP passwords (CVE-2026-14502), all CVSS 9.8; upgrade to 10.5.0.23, 10.6.0.11 or 11.0.0.3
IBM's security bulletin for DataPower Gateway, first published on 28 September 2026, fixes 36 CVEs; the CVE records went public on 8 October 2026. DataPower is a security and integration gateway often placed at the network edge in front of APIs, web services and mainframe systems. Flaws rated CVSS 9.8 include CVE-2026-16340 (out-of-bounds write in the RFC 2047 encoded-word parser allowing a remote attacker to run code), CVE-2026-15762 (out-of-bounds write allowing remote code execution), CVE-2026-14269 (heap-based buffer overflow letting an unauthenticated remote attacker run code), CVE-2026-14502 (a remote attacker can gain administrative access because empty passwords are not rejected during LDAP authentication) and buffer overflows CVE-2026-14991 and CVE-2026-14992 (IBM's text for CVE-2026-14991 describes a local user). Affected: 10.5.0.0 to 10.5.0.22, 10.6.0.0 to 10.6.0.10, 10.6CD 10.6.1 to 10.6.6, and 11.0.0.0 to 11.0.0.2. IBM lists no workarounds, flags known issue DT499224, and reports no exploitation. Primary: IBM.
- Product
- IBM DataPower Gateway
- Versions
- 10.5.0.0–10.5.0.22; 10.6.0.0–10.6.0.10; 10.6CD 10.6.1–10.6.6; 11.0.0.0–11.0.0.2
- CVSS
- (CVE-2026-16340, CVE-2026-15762, CVE-2026-14269, CVE-2026-14502, CVE-2026-14991, CVE-2026-14992)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade to 10.5.0.23 (10.5.0 stream), 10.6.0.11 (10.6.0 stream) or 11.0.0.3 (10.6CD and 11.0.0 streams). There is no workaround; until upgraded, check LDAP authentication settings, restrict access to the management interfaces, and read known issue DT499224 before upgrading.
Primary: IBM — Security Bulletin: IBM DataPower Gateway multiple vulnerabilities (28 Sep 2026; CVE records published 8 Oct 2026) · CVE: CVE-2026-16340, CVE-2026-14269, CVE-2026-14502, CVE-2026-15762, CVE-2026-14991, CVE-2026-14992 · NVD — CVE-2026-16340 (CNA IBM, published 8 Oct 2026)
