CVE-2026-18163

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 4 mentions (2026-09-23); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-09-23: 4Mentions · 2026-09-24: 109-2309-24
Referenced assets5 URLs
Full discourse5 posts
  • VulDB 🛡@vuldb

    A severe vulnerability was disclosed for IBM Financial Transaction Manager (CVE-2026-18163) https://vuldb.com/vuln/408788

    00031112
    2.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 IBM FTM FOR OPENSHIFT: CRITICAL BULLETIN WITH UNAUTH RCE (CVE-2026-18163 / CVE-2026-18162) IBM published a Critical security bulletin for Financial Transaction Manager (FTM) for Red Hat OpenShift covering a large multi-CVE batch. Lead issues include: * CVE-2026-18163 — unauthenticated remote code execution via improper deserialization (CVSS 9.8) * CVE-2026-18162 — unauthenticated remote code execution via code injection in the `new Function` constructor (CVSS 9.8) Also notable in the same bulletin: CVE-2026-18169 authenticated path traversal (CVSS 9.9) and CVE-2026-17635 missing authentication (CVSS 9.1), among ~40+ CVEs total. Affected: FTM for Red Hat OpenShift 4.0.6.0 through 4.0.10.0 (including 4.0.6.0 iFix6 Refresh). Fix: upgrade to FTM 4.0.11.0. ⚠️ Analyst Note: This is an official IBM Critical security bulletin for a payment-routing platform, not a dark-web leak claim. Coverage reviewed so far does not confirm in-the-wild exploitation. Niche product, but high impact where FTM is deployed. Primary: https://www.ibm.com/support/pages/node/7288641 #DDW #DarkWeb #IBM #FTM #OpenShift #CVE202618163 #CVE202618162 #RCE #ThreatIntelligence #CyberSecurity

    000125.6K
    204.9K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs

    CVE-2026-18163 IBM Financial Transaction Manager Unauthenticated RCE could compromise payment-processing backends and affect transaction integrity in affected IBM FTM deployments Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-09-22/TIER_2_CVE-2026-18163.md #CyberSecurity #FinTech #VulnerabilityManagement

    0000019
    62 followersView on X
  • CERT-PY@CERTpy

    ⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-18169 ❗ CVE-2026-18163 ❗ CVE-2026-18162 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ibm-11/ https://t.co/sMWOURdBAv

    00000184
    6.7K followersView on X
  • The Daily Tech Feed@dailytechonx

    Massive risk in payment processing: IBM’s Financial Transaction Manager suffered multiple vulnerabilities—including CVE-2026-18163 & 18162—that allow remote code execution, unauthorized payment changes, and data exposure. If you use FTM 4.0.6.0-4.0.10.0, updating to 4.0.11.0 is critical. Prioritize authorization hygiene, monitor operator workflows, and secure management interfaces to stop attackers in their tracks. #Cybersecurity #FTM #RCE #IBM #PaymentSecurity #Vulnerabilities https://thedailytechfeed.com/ibm-patches-critical-flaws-in-financial-transaction-manager-amidst-rce-risk/

    0000059
    738 followersView on X

Explore more