IBM FTM for Red Hat OpenShift: multi-CVE bulletin (CVSS to 9.9) — unauth RCE CVE-2026-18163/18162; fix 4.0.11.0
IBM Security Bulletin ibm17288641 (node 7288641; Initial Publish 21 September 2026; Modified 21 Sep) addresses a large set of vulnerabilities in Financial Transaction Manager (FTM) for Red Hat OpenShift. Highest scores: CVE-2026-18169 CVSS 9.9 (authenticated symlink/path validation → sensitive data / integrity, scope changed), CVE-2026-18163 CVSS 9.8 (unauth remote deserialization RCE), CVE-2026-18162 CVSS 9.8 (unauth code injection via JS Function constructor), plus further Critical/High issues (e.g. CVE-2026-17635 9.1 HTTP security-header misconfig; CVE-2026-18872 9.3 stored XSS; CVE-2026-17645 9.1 priv escalation). Affected: FTM for OpenShift 4.0.6.0 through 4.0.10.0 (incl. 4.0.6.0 iFix6 / Operator 4.4.6+20260807.081800). Remediation: upgrade to FTM 4.0.11.0. No exploitation-in-the-wild claim in the bulletin. Primary: IBM bulletin; metadata: CVE.report; wire: Cyber Security News 23 Sep 2026.
- Product
- IBM Financial Transaction Manager (FTM) for Red Hat OpenShift
- Versions
- Affected 4.0.6.0–4.0.10.0 (incl. 4.0.6.0 iFix6 / Operator 4.4.6+20260807.081800). Fix: FTM 4.0.11.0.
- CVSS
- (CVE-2026-18169 CVSS 3.1 Critical, IBM); also 9.8 (CVE-2026-18163 / CVE-2026-18162)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade FTM for Red Hat OpenShift deployments to 4.0.11.0 per IBM bulletin 7288641
Primary: IBM Security Bulletin — FTM for Red Hat OpenShift multiple vulnerabilities (21 Sep 2026) · Vendor: IBM — node 7288641 / ibm17288641 · CVE: CVE-2026-18163, CVE-2026-18169, CVE-2026-18162, CVE-2026-17635, CVE-2026-18872, CVE-2026-17645 · CVE.report — CVE-2026-18163 (and sibling FTM CVEs); also Cyber Security News 23 Sep 2026
