TL;DR
On September 23, 2026, IBM published a security bulletin addressing 47 vulnerabilities in Financial Transaction Manager. These critical IBM FTM vulnerabilities allow attackers to bypass authentication and execute arbitrary code. Financial institutions must upgrade their OpenShift deployments to version 4.0.11.0 immediately.
- Total: 33 CVEs
- Severity: 5 Critical · 18 High · 9 Medium · 1 Low
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-18169
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-18169 | 9.9 | CWE-22 | Not exploited |
| CVE-2026-18163 | 9.8 | CWE-502 | Not exploited |
| CVE-2026-18162 | 9.8 | CWE-94 | Not exploited |
| CVE-2026-17635 | 9.1 | CWE-306 | Not exploited |
| CVE-2026-17645 | 9.1 | CWE-269 | Not exploited |
| CVE-2026-17644 | 8.8 | CWE-798 | Not exploited |
| CVE-2026-17637 | 8.8 | CWE-502 | Not exploited |
| CVE-2026-17643 | 8.8 | CWE-522 | Not exploited |
Why It Matters
IBM Financial Transaction Manager manages high-volume electronic payment routing across global banking networks. Industry telemetry estimates that hundreds of major commercial banks and payment processors run this software. Therefore, security defects in this platform threaten payment integrity and financial stability. Several vulnerabilities carry critical CVSS scores reaching up to 9.9. For instance, an attacker could trigger unauthorized fund transfers or alter transaction logs. Fortunately, security teams have confirmed no active exploitation in the wild. Furthermore, researchers have not published any public proof-of-concept exploit code. Nevertheless, the vast number of severe flaws creates an unacceptable risk for banking environments.
How The Attack Works
The advisory details multiple exploit paths across the application stack. Attackers can combine these weaknesses to breach container environments.
Remote Code Execution And Deserialization
Several flaws permit code execution without valid credentials. For example, CVE-2026-18163 stems from unsafe deserialization of untrusted data. Another weakness involves improper input sanitization in the JavaScript runtime. An attacker can inject malicious code into the Function constructor to run arbitrary commands. Additionally, the PayDir module exposes a vulnerable Java remote method endpoint. An adjacent attacker can deliver crafted serialized payloads to take over the application server.
Authentication Bypasses And AI Runbook Poisoning
The platform also suffers from broken access controls and hardcoded secrets. Multiple endpoints fail to verify cryptographic signatures or validate mutual TLS connections. In the user interface, stored scripting flaws threaten administrative sessions. The advisory warns that “a malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.”
Furthermore, the platform’s artificial intelligence components introduce modern threat vectors. Attackers can poison internal data stores without authentication. The advisory notes that “an unauthenticated attacker can insert malicious runbook content into the agent’s vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.” Finally, symbolic link flaws tracked as CVE-2026-18169 allow attackers to extract sensitive system files.
Affected Versions
These IBM FTM vulnerabilities affect Financial Transaction Manager for RedHat OpenShift versions 4.0.6.0 through 4.0.10.0. The flaw also impacts version 4.0.6.0 iFix6 Refresh deployments.
Patch Or Mitigation Steps
Financial institutions should apply official vendor updates without delay. In its security bulletin, the vendor stated that “IBM Financial Transaction Manager (FTM) has addressed the following vulnerabilities.” Furthermore, the company noted that “IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments.” Administrators must upgrade to version 4.0.11.0 to eliminate exposure. Review the full IBM security advisory for detailed upgrade instructions. Security teams must also restrict access to internal cluster management ports.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!