


Perceptive Security
SOC/SIEM Consultancy

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserializat…
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 22:07:35
Source:
nvd.nist.gov
Enterprise Applications, Zero-Day Vulnerabilities
CVE-2026-12118 is a critical vulnerability affecting IBM webMethods Integration (on-premises) versions 10.15 and 10.11. The flaw allows an unauthenticated remote attacker to execute arbitrary code on the affected system. The root cause is the deserialization of untrusted data, a well-known and dangerous vulnerability class. No authentication is required to exploit this vulnerability, making it particularly severe. The vulnerability has been assigned a high criticality rating. IBM has published a support advisory with remediation guidance. The vulnerability is currently awaiting full analysis by NVD. Organizations running the affected versions should review IBM's advisory and apply patches promptly.
Technical details
Mitigation steps:
Affected products:
IBM webMethods Integration 10.15
IBM webMethods Integration 10.11
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
