IBM known exploited vulnerabilities
CISA lists 8 IBM CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-08-04), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2022-47986 (Aspera Faspex): EPSS 100.0%, added 2023-02-21
- CVE-2015-7450 (WebSphere Application Server and Server Hypervisor Edition): EPSS 97.8%, added 2022-01-10
- CVE-2019-4716 (Planning Analytics): EPSS 86.4%, added 2021-11-03
- CVE-2020-4427 (Data Risk Manager): EPSS 70.0%, added 2021-11-03
- CVE-2020-4430 (Data Risk Manager): EPSS 68.5%, added 2021-11-03
Most affected IBM products
Data Risk Manager (3), Langflow (1), Aspera Faspex (1), InfoSphere BigInsights (1), WebSphere Application Server and Server Hypervisor Edition (1), Planning Analytics (1).
All IBM CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-9198 | Langflow | Langflow Code Injection | 2026-08-04 | 2026-08-07 | 28.7% | – |
| CVE-2022-47986 | Aspera Faspex | Aspera Faspex Code Execution | 2023-02-21 | 2023-03-14 | 100.0% | Yes |
| CVE-2013-3993 | InfoSphere BigInsights | InfoSphere BigInsights Invalid Input | 2022-05-25 | 2022-06-15 | 4.8% | Yes |
| CVE-2015-7450 | WebSphere Application Server and Server Hypervisor Edition | WebSphere Application Server and Server Hypervisor Edition Code Injection. | 2022-01-10 | 2022-07-10 | 97.8% | – |
| CVE-2020-4430 | Data Risk Manager | Data Risk Manager Directory Traversal | 2021-11-03 | 2022-05-03 | 68.5% | – |
| CVE-2020-4428 | Data Risk Manager | Data Risk Manager Remote Code Execution | 2021-11-03 | 2022-05-03 | 61.7% | – |
| CVE-2020-4427 | Data Risk Manager | Data Risk Manager Security Bypass | 2021-11-03 | 2022-05-03 | 70.0% | – |
| CVE-2019-4716 | Planning Analytics | Planning Analytics Remote Code Execution | 2021-11-03 | 2022-05-03 | 86.4% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors