CyberMax
Home › Exploited CVEs

IBM known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 8 IBM CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-08-04), and 2 are known to be used in ransomware campaigns.

IBM CVEs added to CISA KEV per year
2021: 4202142022: 2202222023: 1202312026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected IBM products

Data Risk Manager (3), Langflow (1), Aspera Faspex (1), InfoSphere BigInsights (1), WebSphere Application Server and Server Hypervisor Edition (1), Planning Analytics (1).

All IBM CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-9198LangflowLangflow Code Injection2026-08-042026-08-0728.7%–
CVE-2022-47986Aspera FaspexAspera Faspex Code Execution2023-02-212023-03-14100.0%Yes
CVE-2013-3993InfoSphere BigInsightsInfoSphere BigInsights Invalid Input2022-05-252022-06-154.8%Yes
CVE-2015-7450WebSphere Application Server and Server Hypervisor EditionWebSphere Application Server and Server Hypervisor Edition Code Injection.2022-01-102022-07-1097.8%–
CVE-2020-4430Data Risk ManagerData Risk Manager Directory Traversal2021-11-032022-05-0368.5%–
CVE-2020-4428Data Risk ManagerData Risk Manager Remote Code Execution2021-11-032022-05-0361.7%–
CVE-2020-4427Data Risk ManagerData Risk Manager Security Bypass2021-11-032022-05-0370.0%–
CVE-2019-4716Planning AnalyticsPlanning Analytics Remote Code Execution2021-11-032022-05-0386.4%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors