securityonline.info 23 Sept 2026, 03:25 UTC

IBM FTM Flaws Put OpenShift Payment Systems at Risk of Code Execution

IBM FTM Flaws Put OpenShift Payment Systems at Risk of Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

IBM published a security bulletin on 23 September 2026 covering vulnerabilities in Financial Transaction Manager (FTM) for Red Hat OpenShift. The article gives conflicting totals, referring to 47 vulnerabilities in its introduction but listing 33 CVEs: five critical, 18 high, nine medium and one low. The highest-rated issue is CVE-2026-18169, scored 9.9 under CVSSv3. Other notable flaws include CVE-2026-18163 and CVE-2026-18162, both rated 9.8. No active exploitation or public proof-of-concept code had been confirmed.

The reported weaknesses include unauthorised code execution through unsafe deserialisation and JavaScript input handling, a vulnerable Java remote method endpoint, broken access controls, hardcoded secrets and inadequate signature or mutual-TLS validation. Stored scripting flaws could enable session hijacking and unauthorised operator-level payment actions.

The article also says attackers could poison an AI runbook vector database to influence tool calls, potentially causing unauthorised payment actions or payment-data theft. CVE-2026-18169 involves symbolic-link flaws that may expose sensitive system files.

Affected deployments are FTM for Red Hat OpenShift versions 4.0.6.0 through 4.0.10.0, including version 4.0.6.0 iFix6 Refresh. IBM recommends upgrading to version 4.0.11.0 and reviewing its security advisory for upgrade instructions. The article additionally recommends restricting access to internal cluster-management ports.

View full article

Article by CyberSIXT