IBM DataPower Gateway: Three Critical Vulnerabilities with CVSS 9.8
This text was generated using artificial intelligence (AI).IBM has published three critical vulnerabilities for DataPower Gateway: CVE-2026-14992, CVE-2026-14502 and CVE-2026-14269. All three entries have a CVSS score of 9.8. According to IBM, the vulnerabilities are network-based, exploitable without prior authentication and without user interaction. At the time of publication, IBM had no reports of active exploitation of the vulnerabilities.
The vulnerabilities affect several release lines of IBM DataPower Gateway. IBM provided the fixes on September 25, 2026.
CVE-2026-14992 describes an Out-of-Bounds Write in IBM DataPower Gateway. The flaw is classified as CWE-787 and affects a write access outside the intended memory area.
CVE-2026-14502: LDAP Authentication with Empty Passwords
CVE-2026-14502 concerns LDAP authentication. IBM states that empty passwords are not rejected. A remote attacker could gain administrative access as a result. The vulnerability is classified as CWE-287, Improper Authentication.
The LDAP configuration therefore requires a separate review. A firmware update and the control of LDAP authentication address different technical aspects.
CVE-2026-14269: Heap-Based Buffer Overflow
CVE-2026-14269 is a heap-based buffer overflow that occurs due to insufficient boundary checking. According to IBM, an unauthenticated remote attacker could overflow the memory area and execute arbitrary code on the system.
Affected release lines and available fix versions
IBM provided fixes for all affected release lines on September 25, 2026. The following overview shows the relevant fix versions:
Affected IBM DataPower Gateway release line
IBM specified fix version
10.5.0.0 to 10.5.0.22
10.5.0.23 or 10.5.0.23R
10.6.0.0 to 10.6.0.10
10.6.0.11
10.6.1 to 10.6.6
10.6.7
11.0.0.0 to 11.0.0.2
11.0.0.3
The fix versions should be checked against the fix pack pages provided by IBM for the deployed release line.
Measures for affected environments
Assessing impact: Check installed DataPower Gateway versions and patch levels on deployed systems.
Evaluate fix levels: Review and apply the fixes provided by IBM for the respective release series.
Check LDAP authentication: Verify LDAP configurations for handling empty passwords. If necessary, LDAP authentication may be temporarily restricted.
Limit administrative access: Restrict access to administrative DataPower functions through firewall rules and segmentation.
Establish upgrade planning: For long-term upgrade planning, a current fix level is available with the 11.0.0.x series; whether this stream is classified as the preferred long-term path should be verified based on the current IBM product documentation.
Restricting administrative access may reduce availability. However, it does not eliminate the memory errors or the issue with LDAP authentication. Therefore, the fixes provided by IBM remain relevant for the affected release series.
Classification for external systems
For publicly accessible DataPower Gateway instances, both the patch level and the accessibility and configuration of administrative functions are relevant. The three CVEs affect the same product family but have different root causes: two memory errors and one error in LDAP authentication.
The technical assessment should therefore answer at least three questions:
Which DataPower Gateway instances are deployed?
Which of these instances are reachable from outside?
What is the release series, fix level, and LDAP configuration in place?
IBM DataPower Gateway is often used in enterprise and financial environments. Organizations in Germany and Austria that fall under NIS-2 or the Austrian NISG should check if affected DataPower Gateway instances are operated in critical services. In Switzerland, the reporting obligation applies under the revised Information Security Act (ISG) to the Federal Office for Cybersecurity (BACS). If a security incident occurs due to one of these vulnerabilities related to personal data of EU citizens, the GDPR reporting obligation under Art. 33 applies with a deadline of 72 hours to the responsible supervisory authority.
Visibility and supplier risk
LocateRisk EASM can make visible where DataPower Gateway is used in your publicly accessible infrastructure and whether a system is reachable under a customer domain. This visibility supports the assignment of systems for patch planning; it does not replace a review of the actually installed fix level.
Additionally, C-VRM can incorporate critical security notifications from technology providers and changes in their security level into the assessment of supplier risks. For IBM DataPower Gateway, this complements the view of one's externally accessible systems and the assessment of a security-relevant manufacturer event.
Am I affected?
This affects IBM DataPower Gateway in the versions mentioned above; the vulnerability has been fixed in 10.5.0.23, 10.5.0.23R, 10.6.0.11, 10.6.7, 11.0.0.3. If you want to know whether IBM DataPower Gateway is visible in your publicly accessible infrastructure at all, you can refer to the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
This affects versions 10.5.0.0 to 10.5.0.22, 10.6.0.0 to 10.6.0.10, 10.6.1 to 10.6.6 and 11.0.0.0 to 11.0.0.2. IBM provides fixes for all affected lines.
All three vulnerabilities — CVE-2026-14992, CVE-2026-14502, and CVE-2026-14269 — are classified as critical with a CVSS score of 9.8. They are network-based and exploitable without prior authentication and without user interaction.
At the time of publication of the IBM Security Bulletins, there were no reports of active exploitation of the three vulnerabilities. Due to the high CVSS score and the lack of prerequisites for exploitation, the prompt application of the available patches is still strongly recommended.
Status: October 08, 2026. This contribution serves general informational purposes and is not legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-14992
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.