TL;DR
IBM has disclosed three critical vulnerabilities across three products, each rated CVSS 9.8. The flaws affect App Connect Enterprise, Power HMC, and webMethods Integration. Two of them let attackers execute arbitrary commands or code without logging in. IBM reports no exploitation in the wild for any of the three.
- Product: IBM (3 products)
- Vulnerabilities: 3 flaws (CVE-2026-12943, CVE-2026-12118, CVE-2026-15435)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: This Power Hardware Management Console update is being released to address
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-12943 | 9.8 | CWE-78 | — | Not exploited |
| CVE-2026-12118 | 9.8 | CWE-502 | — | Not exploited |
| CVE-2026-15435 | 9.8 | CWE-22 | — | Not exploited |
Why it matters
These IBM critical vulnerabilities sit in enterprise integration and management tools. Large organizations use these systems to connect internal services and control Power hardware. A single unauthenticated flaw can therefore open a wide door. Moreover, all three carry a near-maximum 9.8 score. So patching should move to the top of the list.
How the attacks work
Power HMC command injection (CVE-2026-12943)
CVE-2026-12943 affects the Power Hardware Management Console. IBM says an unauthenticated user could “execute arbitrary commands with elevated privileges” because of improper input validation. The same issue also touches Novalink management systems.
webMethods deserialization RCE (CVE-2026-12118)
CVE-2026-12118 lives in a bundled testing package called WmServiceMock. According to IBM’s advisory, the flaw stems from deserialization of untrusted data. Researchers at Black Lantern Security found that an unauthenticated attacker can upload and run arbitrary Java code through the deserialization endpoint. No credentials are needed.
App Connect Enterprise file write (CVE-2026-15435)
CVE-2026-15435 is a path traversal flaw in App Connect Enterprise. An attacker sends a crafted URL with “dot dot” sequences to write files anywhere on the system. That foothold can then lead to further compromise.
Affected versions
App Connect Enterprise 12.0.1.0–12.0.12.27 and 13.0.1.0–13.0.7.2 are affected. Power HMC V10.3.1050.0–V10.3.1064.0 and V11.1.1110.0–V11.1.1112.0 are vulnerable. webMethods Integration Server 10.11 and 10.15 ship the risky package.
Patch and mitigation
For App Connect Enterprise, apply fix pack 12.0.12.28 or 13.0.8.0. For Power HMC, install the updates on IBM Fix Central. For webMethods, IBM offers no code patch. Instead, remove the WmServiceMock package from every production and internet-facing node. With these steps, all three IBM critical vulnerabilities now have a clear path to remediation.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.