
🚨 IBM FTM FOR OPENSHIFT: CRITICAL BULLETIN WITH UNAUTH RCE (CVE-2026-18163 / CVE-2026-18162) IBM published a Critical security bulletin for Financial Transaction Manager (FTM) for Red Hat OpenShift covering a large multi-CVE batch. Lead issues include: * CVE-2026-18163 — unauthenticated remote code execution via improper deserialization (CVSS 9.8) * CVE-2026-18162 — unauthenticated remote code execution via code injection in the `new Function` constructor (CVSS 9.8) Also notable in the same bulletin: CVE-2026-18169 authenticated path traversal (CVSS 9.9) and CVE-2026-17635 missing authentication (CVSS 9.1), among ~40+ CVEs total. Affected: FTM for Red Hat OpenShift 4.0.6.0 through 4.0.10.0 (including 4.0.6.0 iFix6 Refresh). Fix: upgrade to FTM 4.0.11.0. ⚠️ Analyst Note: This is an official IBM Critical security bulletin for a payment-routing platform, not a dark-web leak claim. Coverage reviewed so far does not confirm in-the-wild exploitation. Niche product, but high impact where FTM is deployed. Primary: https://www.ibm.com/support/pages/node/7288641 #DDW #DarkWeb #IBM #FTM #OpenShift #CVE202618163 #CVE202618162 #RCE #ThreatIntelligence #CyberSecurity
