Vulnerability intelligence
CVE-2026-3660
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.6%
Riskier than 44% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered May 28, 2026 · latest May 28, 2026
Coverage timeline
-
IBM patches CVE-2026-3660 flaw in Jazz Foundation platformsecurityonline.info · May 28, 2026