IBM security advisory (AV26-922)

HighCVSS 8.8Canadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
HighCVSS 8.8
Used in attacks
Not on CISA’s list
Flaws named
CVE-2026-13293
Vendors and products
IBM
Reported by
1 outlet

As of September 14, 2026, IBM is affected by vulnerabilities in the following products:

  • Langflow OSS
    • Prior to or equal to 1.10.0
    • Prior to or equal to 1.10.2
    • Prior to or equal to 1.11.2
    • Prior to or equal to 1.11.5
  • MQ
    • 10.0.0.0
    • Prior to or equal to 9.1.0.37 LTS
    • Prior to or equal to 9.2.0.43 LTS
    • Prior to or equal to 9.3.0.41 LTS
    • Prior to or equal to 9.3.5.1 CD
    • Prior to or equal to 9.4.0.25 LTS
    • Prior to or equal to 9.4.5.1 CD
  • Sterling File Gateway
    • Prior to or equal to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • Product not named yet

    IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-15 14:29 UTC

Related stories