securityonline.info 8 Oct 2026, 14:42 UTC

IBM Patches 23 DataPower Gateway Flaws, Including Four Critical Bugs

IBM Patches 23 DataPower Gateway Flaws, Including Four Critical Bugs
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

IBM has released patches for 23 DataPower Gateway vulnerabilities across two IBM security bulletins, including four rated as Critical. The flaws span remote code execution, out-of-bounds writes and a cross-site scripting issue in the Web UI. The most severe CVSS 9.8 flaws are CVE-2026-15762 and CVE-2026-16340 (both out-of-bounds write vulnerabilities), along with CVE-2026-14991, which also scores 9.8 and relates to an out-of-bounds write or local code execution depending on the source vector.

An unauthenticated cross-site scripting flaw, CVE-2026-14990 (score 9.3), affects the DataPower 10.6.x line. The article notes that, as of its publication, exploitation had not been publicly confirmed for these flaws, though several are reachable over the network without credentials.

The affected products include multiple DataPower Gateway releases, with fixed versions listed as: 10.5.0[.]23 for 10.5.0.x, 10.6.0[.]11 for 10.6.0.x, and 11.0.0[.]3 for 10.6.1 through 11.0.0[.]2 (11.0.0[.]0 through 11.0.0[.]2). The 10.6CD continuous-delivery track must move to 11.0.0[.]3. IBM states there are no workarounds for these flaws, and administrators should upgrade promptly. In the meantime, organisations should limit access to the DataPower Web UI to trusted administrators until patches are applied. The bulletin reiterates that DataPower Gateway sits at the network edge, so an unpatched flaw could expose protected systems.

View full article

Article by CyberSIXT