Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate patch
AI Analysis

Impact

A buffer overflow in IBM DataPower Gateway allows an out‑of‑bounds write that can lead to arbitrary code execution or denial of service. The flaw is categorized as CWE‑787 and can be triggered when a gateway process handles malformed input.

Affected Systems

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1.0 through 10.6.6.0, and 11.0.0.0 through 11.0.0.2 are affected. The vulnerability has been fixed in revisions beginning with IBM DataPower Gateway 10.6CD 10.6.1, 10.6.6.1, 11.0.0.21, 10.5.0.23, and 10.6.0.101.

Risk and Exploitability

The CVSS score of 9.8 marks this a critical risk, and the EPSS score is currently unavailable, indicating limited data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog, but the severity and lack of mitigation could still lead to successful exploits. Likely attack vectors involve remote ingestion of crafted traffic to the gateway’s management or data interfaces, enabling an attacker to trigger the overflow and gain arbitrary code execution.

Generated by OpenCVE AI on October 8, 2026 at 16:22 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade to IBM DataPower Gateway 10.6CD 10.6.1 or later, 10.6.6.1 or later, 11.0.0.21 or later, 10.5.0.23 or later, or 10.6.0.101 or later.
  • If an upgrade cannot be performed immediately, limit external exposure of the gateway by restricting access to trusted IP ranges and auditing all inbound traffic for anomalies.
  • Monitor gateway logs for signs of abnormal activity such as failed authentication attempts or unexpected protocol behavior, and apply additional hardening measures such as disabling unused services and enforcing strong authentication.

Generated by OpenCVE AI on October 8, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:32:59.397Z

Reserved: 2026-07-07T18:49:08.227Z

Link: CVE-2026-14992

cve-icon Vulnrichment

Updated: 2026-10-08T14:32:56.613Z

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:50.210

Modified: 2026-10-08T15:17:50.210

Link: CVE-2026-14992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses