TL;DR
IBM has released fixes for 23 IBM DataPower Gateway vulnerabilities across two security bulletins. Four rate Critical, including two remote code execution flaws scored 9.8 that need no login. IBM “strongly advises upgrading as soon as possible.”
- Total: 23 CVEs
- Severity: 4 Critical · 17 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-14991
- Action: Apply the latest security updates now
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-14991 | 9.8 | DataPower Gateway Out-of-bounds Write | Not exploited |
| CVE-2026-15762 | 9.8 | DataPower Gateway Out-of-bounds Write | Not exploited |
| CVE-2026-16340 | 9.8 | CWE-787 | Not exploited |
| CVE-2026-14990 | 9.3 | DataPower Gateway affected by cross-site scripting | Not exploited |
| CVE-2026-16159 | 8.6 | DataPower Gateway Out-of-bounds Write | Not exploited |
| CVE-2026-16163 | 8.6 | DataPower Gateway Out-of-bounds Write | Not exploited |
| CVE-2026-15824 | 8.2 | DataPower Gateway Denial of Service | Not exploited |
| CVE-2026-15784 | 8.1 | DataPower Gateway Out-of-bounds Write | Not exploited |
Why It Matters
DataPower Gateway is IBM’s security and integration appliance for APIs, web services and business-to-business traffic. It typically sits at the edge of a network, in front of the systems it protects. As a result, a flaw in the gateway can expose the systems it is meant to protect.
Most of these bugs are reachable over the network without credentials. Of the 23, IBM rates four Critical, 17 High and two Medium. The CVE records list the exploitation status as unknown, and no public proof-of-concept has been confirmed.
How the Attacks Work
Remote Code Execution
CVE-2026-15762 and CVE-2026-16340 both score 9.8. Each could “allow a remote attacker to execute arbitrary code due to an out-of-bounds write.” The second bug sits in the RFC 2047 encoded-word parser, which decodes text in email-style headers. Meanwhile, CVE-2026-15784 (8.1) and CVE-2026-15781 (8.0) are further code execution bugs, though both are harder to trigger.
A Confusing Fourth Critical Bug
CVE-2026-14991 also scores 9.8 as an out-of-bounds write. However, its description says “a local user could overflow the buffer and execute arbitrary code on the system.” That conflicts with its network-based CVSS vector. Either way, it is one more reason to treat these IBM DataPower Gateway vulnerabilities as urgent.
Web UI Cross-Site Scripting
The separate bulletin covers CVE-2026-14990, rated 9.3. It lets an unauthenticated user “embed arbitrary JavaScript code in the Web UI.” According to IBM, that could lead to “credentials disclosure within a trusted session.” This flaw affects only the 10.6.0 branch.
Crashes and Data Leaks
Most of the remaining IBM DataPower Gateway vulnerabilities cause a denial of service. They stem from buffer overflows, null pointer dereferences, type confusion and out-of-bounds reads. Two involve GraphQL processing. Separately, CVE-2026-16181 allows an attacker to bypass security restrictions, and CVE-2026-16177 can leak sensitive data.
Affected Versions
The main IBM security bulletin lists these affected releases:
- 10.5.0.0 through 10.5.0.22, fixed in 10.5.0.23
- 10.6.0.0 through 10.6.0.10, fixed in 10.6.0.11
- 10.6.1 through 10.6.6 (10.6CD), fixed in 11.0.0.3
- 11.0.0.0 through 11.0.0.2, fixed in 11.0.0.3
Patch and Mitigation Steps
Upgrade to the fixed release for your branch. The CVE records list no workarounds for these flaws. Users on the 10.6CD continuous-delivery track must move to 11.0.0.3. In addition, limit access to the DataPower Web UI to trusted administrators until the patch is in place.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!