CVE-2026-18169

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-23: 209-23
Referenced assets2 URLs
Full discourse2 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 IBM FTM FOR OPENSHIFT: CRITICAL BULLETIN WITH UNAUTH RCE (CVE-2026-18163 / CVE-2026-18162) IBM published a Critical security bulletin for Financial Transaction Manager (FTM) for Red Hat OpenShift covering a large multi-CVE batch. Lead issues include: * CVE-2026-18163 — unauthenticated remote code execution via improper deserialization (CVSS 9.8) * CVE-2026-18162 — unauthenticated remote code execution via code injection in the `new Function` constructor (CVSS 9.8) Also notable in the same bulletin: CVE-2026-18169 authenticated path traversal (CVSS 9.9) and CVE-2026-17635 missing authentication (CVSS 9.1), among ~40+ CVEs total. Affected: FTM for Red Hat OpenShift 4.0.6.0 through 4.0.10.0 (including 4.0.6.0 iFix6 Refresh). Fix: upgrade to FTM 4.0.11.0. ⚠️ Analyst Note: This is an official IBM Critical security bulletin for a payment-routing platform, not a dark-web leak claim. Coverage reviewed so far does not confirm in-the-wild exploitation. Niche product, but high impact where FTM is deployed. Primary: https://www.ibm.com/support/pages/node/7288641 #DDW #DarkWeb #IBM #FTM #OpenShift #CVE202618163 #CVE202618162 #RCE #ThreatIntelligence #CyberSecurity

    000125.6K
    204.9K followersView on X
  • CERT-PY@CERTpy

    ⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-18169 ❗ CVE-2026-18163 ❗ CVE-2026-18162 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ibm-11/ https://t.co/sMWOURdBAv

    00000184
    6.7K followersView on X

Explore more