« Back to list

IBM

IBM ART: vulnerabilities and CVEs

IBM ART has 8 published vulnerabilities, 8 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months8
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-1037Medium (6.1)0.20%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary…
CVE-2026-1031Medium (6.1)0.20%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary…
CVE-2026-1030Medium (4.3)0.21%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.
CVE-2026-1029Medium (5.4)0.16%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…
CVE-2026-1025Medium (6.1)0.18%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI…
CVE-2025-15399Critical (10)0.18%—Sep 18, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…
CVE-2026-19543Medium (6.2)0.12%—Sep 14, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side.…
CVE-2026-19646Critical (9.1)0.38%—Sep 10, 2026
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript4
  2. T1189 Drive-by Compromise4
  3. T1190 Exploit Public-Facing Application2
  4. T1005 Data from Local System1
  5. T1210 Exploitation of Remote Services1
  6. T1589.001 Credentials1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by IBM