SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-17444

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM App Connect Enterprise and IBM Integration Bus for z/OS versions specified are vulnerable to an XML external entity (XXE) injection, which could allow remote authenticated attackers to access sensitive information. Organizations using these versions should prioritize patching to mitigate potential data exposure risks. This vulnerability is particularly relevant for enterprises relying on these integration solutions for data processing and management.

CVE
CVE-2026-17444
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

Related CVEs

Other vulnerabilities affecting the same vendor(s)