SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19646

CRITICAL · CVSS 9.1 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Common Licensing Agent and related products are vulnerable to a critical flaw that allows remote attackers to redirect users to arbitrary domains through improper validation of the HTTP Host header. This could lead to phishing attacks or the distribution of malicious content. Organizations using these affected IBM products should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-19646
Severity
CRITICAL
CVSS
9.1
EPSS
0.52%

Original NVD Description

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.