IBM FTM flaw could let unauthenticated attackers manipulate AI tool calls

Forkast News

CVE-2026-18875 in IBM Financial Transaction Manager for Red Hat OpenShift lets unauthenticated attackers poison its AI vector store and steer MCP calls, potentially enabling unauthorized payments or financial-data theft. Versions 4.0.6.0–4.0.10.0 must be upgraded to 4.0.11.0.

IBM’s Sept. 23, 2026 bulletin covers 47 vulnerabilities in FTM for Red Hat OpenShift; CVE-2026-18875 is rated 7.3 on CVSS. The article traces the flaw to a network-based runbook upsert that can add content to the AI agent’s vector database.

The affected range includes iFix6 Refresh. The bulletin also lists CVE-2026-18162, a separate code-injection flaw rated critical at CVSS 9.8.

#IBM-Financial-Transaction-Manager-vulnerability #CVE-2026-18875-fix
Share