← Vulnerability feed

Vulnerability record · CVE-2026-12118 · published 30 July 2026

CVE-2026-12118: Ibm webmethods integration deserialization of untrusted data vulnerability

Ibm · Webmethods Integration

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

9.8 CVSS 3.1 Critical EPSS 0.85% · top 43.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
10 Aug 2026Last modified by NVD

Description

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-12118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-45076Ibm webmethods integration unrestricted file upload vulnerabilityIBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…EPSS 0.55%8.8CVE-2025-36072Ibm webmethods integration deserialization of untrusted data vulnerabilityIBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration…EPSS 0.47%8.8CVE-2025-36202Ibm webmethods integration vulnerabilityIBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to t…EPSS 0.34%8.8CVE-2025-36049Ibm webmethods integration xml external entity (xxe) vulnerabilityIBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML dat…EPSS 0.65%8.8CVE-2024-45075Ibm webmethods integration missing authentication for critical function vulnerabilityIBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to ad…EPSS 0.45%7.2CVE-2025-36048Ibm webmethods integration execution with unnecessary privileges vulnerabilityIBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external enti…EPSS 0.49%6.5CVE-2024-45074Ibm webmethods integration path traversal vulnerabilityIBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted …EPSS 0.48%5.4CVE-2025-36037Ibm webmethods integration server-side request forgery (ssrf) vulnerabilityIBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unaut…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2026-12118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.