IBM DataPower Gateway: multiple critical security vulnerabilities (CVE-2026-16340, CVE-2026-14990)

This text was generated using artificial intelligence (AI).Update 10.08.2026: Additionally, CVE-2026-14990 (CVSS 9.3) has been disclosed, a cross-site scripting vulnerability in the release stream 10.6.0. Details see below.

IBM has disclosed the vulnerability for IBM DataPower Gateway CVE-2026-16340 , documented in the IBM Security Advisory. It carries a CVSS score of 9.8. Affected gateways can be exploited over the network without prior authentication to execute arbitrary code.

According to IBM, the cause lies in an out-of-bounds write of the category CWE-787 in the parser for RFC2047 encoded-word inputs. Specifically crafted inputs can trigger the fault.

Are my systems affected? Check now →