Skip to content

Release roundup

IBM week 36 2026: six CVEs led by a high-severity Verify Identity Access disclosure

High 7.5 Vendor: IBM 6 CVEs in scope Published

IBM's week 36 2026 set covers six CVEs: one high, five medium, with no CVEs in CISA KEV or confirmed exploitation. The priority is CVE-2026-13297, an unauthenticated information disclosure in Verify Identity Access and Security Verify Access. Patch it first, then Db2 Mirror and MQ Agent.

The release at a glance

IBM's vulnerabilities for week 36 of 2026, covering 31 August to 6 September 2026, contain six CVEs: one high and five medium. No CVE in this release is listed in CISA's Known Exploited Vulnerabilities catalog, and none is marked as exploited or publicly disclosed.

Products in scope are Db2 Mirror for i with three CVEs, Verify Identity Access with one, QRadar with one, and MQ Agent with one. The only high-severity issue, CVE-2026-13297, affects Verify Identity Access, Security Verify Access, and the corresponding container editions, and has a separate advisory on this site.

What matters most

Verify Identity Access and Security Verify Access. CVE-2026-13297 is the only high-severity CVE in this release, with a CVSS 3.1 score of 7.5. It is an information disclosure issue in Advanced Access Control. The vector is network-based, with low attack complexity, no privileges, and no user interaction. Affected versions listed are Verify Identity Access 11.0.0 to 11.0.3 Interim Fix 001, Security Verify Access 10.0.0 to 10.0.9.2 Interim Fix 001, and the matching container editions. IBM has issued a separate advisory for this CVE.

QRadar. CVE-2026-5522 affects QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005. The issue is hard-coded credentials used for inbound authentication, outbound communication to external components, or encryption of internal data. CVSS is 6.7 medium, with a local vector and high privileges required.

MQ Agent. CVE-2026-19645 affects IBM MQ Agent CD v1.0.0, v1.0.1, v2.0.0, and v2.0.1. An authenticated user with a valid session cookie can submit computationally expensive requests that hold LLM agent workers from tens of seconds to over ten minutes; concurrent requests can exhaust the worker pool and make the AI Agent feature unavailable. CVSS is 6.5 medium, with a network vector and low privileges required.

Db2 Mirror for i. Three CVEs affect versions 7.4, 7.5, and 7.6. CVE-2026-16660 is a remote denial-of-service caused by an out-of-bounds read, rated 5.3 medium with a network vector and no privileges required. CVE-2026-18567 is a local information disclosure from a race condition involving a predictable Unix domain socket path in a world-writable directory, rated 4.4. CVE-2026-17483 allows a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure, rated 4.3. Patches are available for each; the release data does not state specific fixed version numbers.

Patch in this order

No CVE here is in CISA KEV, so no CISA-directed due date applies. Patch in this order:

  1. Patch CVE-2026-13297 first on Verify Identity Access, Security Verify Access, and the container editions. It is the only high-severity issue, is reachable over the network without credentials, and carries a 7.5 CVSS score. A separate advisory is available.
  2. Patch CVE-2026-16660 on Db2 Mirror for i 7.4, 7.5, and 7.6. It is remote, unauthenticated, and can cause denial of service.
  3. Patch CVE-2026-19645 on IBM MQ Agent CD v1.0.0, v1.0.1, v2.0.0, and v2.0.1 if the AI Agent feature is in use. The network-based denial-of-service requires authentication, making it the next network concern.
  4. Patch CVE-2026-17483 on Db2 Mirror for i 7.4, 7.5, and 7.6 to stop deletion of historical flight-recorder archives.
  5. Patch CVE-2026-5522 on QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005. The local, high-privilege vector lowers immediate urgency, but hard-coded credentials remain a material weakness.
  6. Patch CVE-2026-18567 on Db2 Mirror for i 7.4, 7.5, and 7.6 to close the local race-condition information disclosure.

Beyond the patch

IBM's week 36 set is small and contains no confirmed exploitation, so the task is mainly prioritisation and verification. CVE-2026-13297 is reachable over the network without credentials; Virtual CISO Services (vCISO) can help establish what is exposed and set the patching order. Because the remaining issues sit in IBM products across the estate, Supply Chain Defense & Third-Party Risk helps track vendor advisories and their fixes.

Every CVE in this release

CVEProductSeverity
CVE-2026-13297Verify Identity AccessHigh 7.5Advisory →
CVE-2026-5522QRadarMedium 6.7
CVE-2026-19645MQ AgentMedium 6.5
CVE-2026-16660Db2 Mirror for iMedium 5.3
CVE-2026-18567Db2 Mirror for iMedium 4.4
CVE-2026-17483Db2 Mirror for iMedium 4.3

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.