IBM security advisory (AV26-922)
At a glance
- Severity
- HighCVSS 8.8
- Used in attacks
- Not on CISA’s list
- Flaws named
- CVE-2026-13293
- Vendors and products
- IBM
- Reported by
- 1 outlet
As of September 14, 2026, IBM is affected by vulnerabilities in the following products:
- Langflow OSS
- Prior to or equal to 1.10.0
- Prior to or equal to 1.10.2
- Prior to or equal to 1.11.2
- Prior to or equal to 1.11.5
- MQ
- 10.0.0.0
- Prior to or equal to 9.1.0.37 LTS
- Prior to or equal to 9.2.0.43 LTS
- Prior to or equal to 9.3.0.41 LTS
- Prior to or equal to 9.3.5.1 CD
- Prior to or equal to 9.4.0.25 LTS
- Prior to or equal to 9.4.5.1 CD
- Sterling File Gateway
- Prior to or equal to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1
The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-132938.8High
Product not named yet
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Full record →
Coverage
One outlet has carried this so far.
2026-09-15 14:29 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited