CVE-2026-15762 and CVE-2026-14991 in IBM DataPower Gateway
This text was generated using artificial intelligence (AI).IBM published two critical vulnerabilities for IBM DataPower Gateway on October 08, 2026: CVE-2026-15762 and CVE-2026-14991. Both entries have a CVSS score of 9.8. At the time of publication, the IBM advisory does not list confirmed fix versions; organizations should monitor the advisory directly and check for updates.
The advisories affect the following version ranges of IBM DataPower Gateway:
10.5.0.0 to 10.5.0.22
10.6.0.0 to 10.6.0.10
10.6.1 to 10.6.6
11.0.0.0 to 11.0.0.2
For operational classification, each existing instance should be matched against the IBM advisory. Relevant considerations include the installed version status, patch status, and whether the system is publicly accessible.
CVE-2026-15762: Out-of-Bounds Write with Possible Code Execution
CVE-2026-15762 describes an out-of-bounds write in IBM DataPower Gateway. Such an error occurs when an application writes outside a designated memory area. According to IBM, a remote attacker can thereby execute arbitrary code.
The CVSS score is 9.8. The published rating describes a network-based attack vector with low attack complexity and no permissions required, as well as no user interaction.
CVE-2026-14991: Buffer Overflow Due to Faulty Boundary Checking
At CVE-2026-14991 is reported by IBM as a buffer overflow caused by faulty boundary checking. IBM describes that a local user could overflow the buffer and execute code on the system.
For this entry, a CVSS score of 9.8 has also been published. The CVSS vector indicates a network-based attack vector, while IBM describes a local attacker in the free text – this contradiction in the source material can only be resolved by directly checking the manufacturer advisory.
Patch Status and Prioritization
At the time of this publication, the IBM advisory does not list confirmed fix versions for the affected version ranges. Organizations should monitor the advisory directly and check for updates before planning and implementing changes.
For affected organizations, the following tasks arise:
Capture DataPower Gateway instances and their installed version statuses.
Check the patch status of each affected instance against the IBM advisory.
Prioritize publicly accessible instances for technical review.
Incorporate available fixes into the internal release process as soon as identified.
Handle systems that are still pending updates separately.
Anchor vulnerability and vendor risk monitoring in the operational process.
Check external visibility of DataPower Gateway.
IBM DataPower Gateway can operate under company domains and is externally fingerprintable. Therefore, it is relevant for prioritization which instances are publicly accessible under your own responsibility.
An external inventory helps assign reachable systems to the responsible teams and specifically check their patch status. The technical evaluation of an instance also requires aligning the actual version status with the manufacturer advisory.
Additional regulatory frameworks apply to companies in the DACH region: If an attacker succeeds in accessing personal data through one of these vulnerabilities, the reporting obligation under Art. 33 GDPR applies with a 72-hour deadline to the responsible supervisory authority. NIS-2 duty operators in Germany and Austria – such as in the finance, health, or digital infrastructure sectors – should additionally evaluate vulnerabilities within the framework of their incident management process. For Switzerland, the reporting obligation follows the revised Information Security Act (ISG) to BACS.
Classify LocateRisk: EASM and C-VRM.
LocateRisk makes publicly accessible systems and deployed software visible. In the case of IBM DataPower Gateway, this visibility can help capture externally reachable instances in your corporate context and prioritize them for technical review.
The platform does not automatically determine whether a specific vulnerable version is installed on an instance. The responsible operations and application teams are responsible for version alignment, patch decisions, and implementation.
Additionally, the C-VRM perspective can integrate critical vulnerability reports from technology providers into existing supplier assessments. This allows for structured evaluation of a manufacturer’s security reports and technical dependencies.
Am I affected?
This affects IBM DataPower Gateway in the versions mentioned above. Those who want to know whether IBM DataPower Gateway is even visible in their externally accessible infrastructure can refer to the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-15762 is a critical vulnerability in IBM DataPower Gateway, where an out-of-bounds write can allow a remote attacker to execute arbitrary code on the affected system. The CVSS score is 9.8.
At the time of publication, the IBM advisory does not list any confirmed fixed versions. Organizations should monitor the IBM advisory directly and check for updates.
Status: October 08, 2026. This contribution serves general informational purposes and is not legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-15762
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.