IBM has published fixes for 40 vulnerabilities in its DataPower Gateway, and seven of them carry critical CVSS scores between 9.3 and 9.8. IBM's product security team filed the CVE records, which appeared in the National Vulnerability Database on October 8.
Four release lines are affected. IBM lists DataPower Gateway 10.5.0 (10.5.0.0 through 10.5.0.22), 10.6.0 (10.6.0.0 through 10.6.0.10), 10.6 CD (10.6.1 through 10.6.6) and 11.0.0 (11.0.0.0 through 11.0.0.2). Thirty-seven of the 40 flaws affect all four lines. The exceptions are noted in the lists below.
The fixed releases. According to IBM's bulletins, 10.5.0 users should move to 10.5.0.23 and 10.6.0 users to 10.6.0.11. Both 10.6 CD and 11.0.0 users should move to 11.0.0.3. IBM lists no workarounds or mitigations and "strongly advises upgrading as soon as possible."
Seven critical flaws. Four can lead to code execution, one grants admin access and one is a cross-site scripting bug in the Web UI. IBM's record for the seventh says only that it is a buffer overflow.
• CVE-2026-16340 (CVSS 9.8): remote code execution through an out-of-bounds write in the RFC2047 encoded-word parser.
• CVE-2026-14502 (CVSS 9.8): administrative access because LDAP authentication does not reject empty passwords.
• CVE-2026-14269 (CVSS 9.8): heap-based buffer overflow that lets an unauthenticated remote attacker run arbitrary code.
• CVE-2026-15762 (CVSS 9.8): remote code execution through an out-of-bounds write.
• CVE-2026-14991 (CVSS 9.8): buffer overflow from improper bounds checking. IBM's description says a local user could run arbitrary code, while its CVSS vector scores the flaw as network-exploitable.
• CVE-2026-14992 (CVSS 9.8): buffer overflow. IBM's record gives no further detail.
• CVE-2026-14990 (CVSS 9.3): cross-site scripting in the Web UI by an unauthenticated user, which could expose credentials within a trusted session. Affects 10.6.0.0 through 10.6.0.10 only.
Twenty-four high-severity flaws, mostly denial-of-service bugs, plus several code execution and authentication bypass issues:
• CVE-2026-16159 (CVSS 8.6): out-of-bounds write that could expose sensitive information and cause a denial of service.
• CVE-2026-16163 (CVSS 8.6): memory corruption through an out-of-bounds write.
• CVE-2026-14496 (CVSS 8.2): denial of service through a heap-based buffer overflow.
• CVE-2026-15824 (CVSS 8.2): denial of service through a heap-based buffer overflow.
• CVE-2026-14905 (CVSS 8.2): XML external entity (XXE) injection that could expose sensitive information or consume memory.
• CVE-2026-14497 (CVSS 8.1): security bypass by an authenticated attacker due to improper verification of cryptographic signatures.
• CVE-2026-14888 (CVSS 8.1): remote code execution through a heap-based buffer overflow.
• CVE-2026-15784 (CVSS 8.1): remote code execution through an out-of-bounds write.
• CVE-2026-15781 (CVSS 8.0): remote code execution by an authenticated attacker through a buffer overflow.
• CVE-2026-14507 (CVSS 7.7): denial of service by an authenticated attacker due to improper memory allocation during key derivation. Affects 11.0.0.0 through 11.0.0.2 only.
• CVE-2026-16169 (CVSS 7.5): denial of service through uncontrolled resource consumption. Affects 11.0.0.0 through 11.0.0.2 only.
• CVE-2026-16170 (CVSS 7.5): denial of service through a heap buffer overflow.
• CVE-2026-16176 (CVSS 7.5): denial of service due to improper validation of a length field during memory reallocation.
• CVE-2026-16178 (CVSS 7.5): denial of service due to improper input validation.
• CVE-2026-16179 (CVSS 7.5): heap buffer underwrite that could crash the service.
•
CVE-2026-15819 (CVSS 7.5): denial of service through out-of-bounds memory access in a sorting comparator.
•
CVE-2026-15822 (CVSS 7.5): denial of service due to improper memoization of GraphQL fragment spreads.
•
CVE-2026-16111 (CVSS 7.5): denial of service through a type confusion flaw.
•
CVE-2026-16161 (CVSS 7.5): denial of service through an out-of-bounds read.
•
CVE-2026-16164 (CVSS 7.5): denial of service through a buffer overflow.
•
CVE-2026-16165 (CVSS 7.5): denial of service through a null pointer dereference.
•
CVE-2026-16167 (CVSS 7.5): denial of service due to improper bounds checking.
•
CVE-2026-16181 (CVSS 7.4): security restriction bypass due to improper authorization.
•
CVE-2026-14999 (CVSS 7.4): authentication bypass by forging valid JSON Web Signatures.
Nine medium-severity flaws:•
CVE-2026-13257 (CVSS 6.5): an authenticated user could forge signature requests due to improper verification of data authenticity.
•
CVE-2026-14273 (CVSS 6.5): a local attacker could obtain sensitive information due to improper authorization.
•
CVE-2026-14508 (CVSS 6.5): denial of service and information disclosure through a use-after-free.
•
CVE-2026-14988 (CVSS 6.5): buffer overflow.
•
CVE-2026-16182 (CVSS 5.9): denial of service through a NULL pointer dereference in GraphQL variable processing.
•
CVE-2026-14509 (CVSS 5.9): denial of service from algorithmic complexity in linked-list traversal.
•
CVE-2026-13258 (CVSS 5.4): cross-site scripting in the Web UI by an authenticated user.
•
CVE-2026-16177 (CVSS 5.3): sensitive information exposure through an out-of-bounds read.
•
CVE-2026-14521 (CVSS 4.9): server-side request forgery (SSRF) by an authenticated attacker.
What admins should do. Upgrade each appliance to the fixed release for its line, following IBM's bulletins:
the main bulletin covering 36 of the CVEs,
CVE-2026-14990,
CVE-2026-14507 and CVE-2026-16169 and
CVE-2026-14521. IBM scores the critical code execution and LDAP flaws as exploitable over the network with no credentials or user interaction.
About the scores. All scores above are CVSS 3.1 base scores assigned by IBM. NVD lists the records as received and had not added its own analysis at publication. Neither IBM's bulletins nor the NVD records report active exploitation.