CVE-2026-18490
📛 CVE Title
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- ibm
- CVSS severity
- HIGH
- CVSS score
- 8.8 / 10
- CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-502 - Reserved
- 2026-07-31
- Published
- 2026-09-23 15:45 UTC
- Last updated
- 2026-09-23 19:44 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/18xxx/CVE-2026-18490.json
- Linked Threat
- CVE-2026-18490 — IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-23 16:16:41 UTC
- NVD last modified
- 2026-09-23 20:17:10 UTC
- NVD CVSS v3.1
- 8.8 / 10 HIGH source: psirt@us.ibm.com
- NVD CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 5.9 / 10
NVD / KEV / EPSS data refreshed 2026-09-24 04:38 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85352 - Assigner
- ibm
- Published
- Sep 23, 2026, 3:45:29 PM
- Updated
- Sep 23, 2026, 7:44:48 PM
- EUVD base score (CVSS 3.1)
-
8.8 / 10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0000
- Vendors
- IBM
- Products
-
Financial Transaction Manager (FTM) for RedHat OpenShift (4.0.6.0 ≤4.0.10.0)
- Aliases
-
GHSA-5p47-frcm-v44p
ENISA description: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IBM | Financial Transaction Manager (FTM) for RedHat OpenShift |
4.0.6.0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.ibm.com/support/pages/node/7288641 vendor-advisorypatch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.ibm.com/support/pages/node/7288641 psirt@us.ibm.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:app.opencve.io
Apply IBM's patch by upgrading Financial Transaction Manager for RedHat OpenShift to version 4.0.11.0 or later. Restrict network access to the PayDir Business Rules Manager RMI SSL service until the patch is applied, using segmentation or firewall rules to limit exposure to trusted hosts.
2026-09-24 11:15 UTC -
web:cvetodo.com
CVE-2026-18490 is a CVSS 8.8 high-severity vulnerability in IBM products. Includes technical details, affected versions, and mitigation steps.
2026-09-24 11:15 UTC -
web:docs.netscaler.com
Remediate CVE - 2026 -19490 For CVE - 2026 -19490 impacted NetScaler instances, the remediation is a single-step process and you need to upgrade the vulnerable NetScaler instances to a release and build that has the fix . In the GUI, under CVE Detection > Impacted Instances, select the instances and click Proceed to upgrade workflow.
2026-09-24 11:15 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-24 11:15 UTC -
web:socradar.io
What Is CVE - 2026 -19490? CVE - 2026 -19490 is an authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway. Cloud Software Group classifies it as CWE-288: Authentication Bypass Using an Alternate Path and assigns it a CVSS v4.0 score of 9.3.
2026-09-24 11:15 UTC -
web:tech-insider.org
CVE - 2026 -19490 lets attackers bypass NetScaler logins with no password. CISA added it to KEV Sept. 9 as Palo Alto, Check Point patch matching flaws.
2026-09-24 11:15 UTC -
web:vulmon.com
Vulnerability Summary IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by an unauthenticated remote code execution vulnerability. An attacker on an adjacent network can send a crafted serialized payload to the PayDir Business Rules Manager RMI SSL endpoint. This flaw enables arbitrary code execution, potentially exposing all PayDir credentials and allowing manipulation ...
2026-09-24 11:15 UTC -
web:www.bleepingcomputer.com
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw ( CVE - 2026 -19490) in the wild, according to vulnerability intelligence company Previdian.
2026-09-24 11:15 UTC -
web:www.rapid7.com
On August 19, 2026 , a security advisory was published for CVE - 2026 -19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.
2026-09-24 11:15 UTC -
web:www.rescana.com
Citrix NetScaler ADC/Gateway CVE - 2026 -19490 is a critical authentication bypass added to CISA KEV on September 9, 2026 . Patch to fixed builds and complete forensic triage.
2026-09-24 11:15 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-18490.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18490",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T18:13:02.634803Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T19:44:48.501Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*"
],
"product": "Financial Transaction Manager (FTM)\u00a0for RedHat OpenShift",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "4.0.10.0",
"status": "affected",
"version": "4.0.6.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.</p>"
}
],
"value": "IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T15:45:29.558Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7288641"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following</p><p></p><div><table><tbody><tr><td>Affected Product(s)</td><td>Resolved by VRMF</td><td>Remediation / First Fix</td></tr><tr><td>Financial Transaction Manager (FTM)\u00a0for RedHat OpenShift</td><td>4.0.11.0</td><td><a href=\"https://www.ibm.com/support/pages/node/7285661\" rel=\"nofollow\">FTM 4.0.11.0</a></td></tr></tbody></table></div>"
}
],
"value": "IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following\n\n\n\n\n\nAffected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM)\u00a0for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661"
}
],
"title": "IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities"
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-18490",
"datePublished": "2026-09-23T15:45:29.558Z",
"dateReserved": "2026-07-31T14:02:24.096Z",
"dateUpdated": "2026-09-23T19:44:48.501Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}