IBM published a security bulletin on 23 September 2026 covering vulnerabilities in Financial Transaction Manager (FTM) for Red Hat OpenShift. The article gives conflicting totals, referring to 47 vulnerabilities in its introduction but listing 33 CVEs: five critical, 18 high, nine medium and one low. The highest-rated issue is CVE-2026-18169, scored 9.9 under CVSSv3. Other notable flaws include CVE-2026-18163 and CVE-2026-18162, both rated 9.8. No active exploitation or public proof-of-concept code had been confirmed.
The reported weaknesses include unauthorised code execution through unsafe deserialisation and JavaScript input handling, a vulnerable Java remote method endpoint, broken access controls, hardcoded secrets and inadequate signature or mutual-TLS validation. Stored scripting flaws could enable session hijacking and unauthorised operator-level payment actions.
The article also says attackers could poison an AI runbook vector database to influence tool calls, potentially causing unauthorised payment actions or payment-data theft. CVE-2026-18169 involves symbolic-link flaws that may expose sensitive system files.
Affected deployments are FTM for Red Hat OpenShift versions 4.0.6.0 through 4.0.10.0, including version 4.0.6.0 iFix6 Refresh. IBM recommends upgrading to version 4.0.11.0 and reviewing its security advisory for upgrade instructions. The article additionally recommends restricting access to internal cluster-management ports.