IBM DataPower Gateway: multiple critical security vulnerabilities (CVE-2026-16340, CVE-2026-14990)
This text was generated using artificial intelligence (AI).Update 10.08.2026: Additionally, CVE-2026-14990 (CVSS 9.3) has been disclosed, a cross-site scripting vulnerability in the release stream 10.6.0. Details see below.
IBM has disclosed the vulnerability for IBM DataPower Gateway CVE-2026-16340 , documented in the IBM Security Advisory. It carries a CVSS score of 9.8. Affected gateways can be exploited over the network without prior authentication to execute arbitrary code.
According to IBM, the cause lies in an out-of-bounds write of the category CWE-787 in the parser for RFC2047 encoded-word inputs. Specifically crafted inputs can trigger the fault.
Patch available since: September 25, 2026 (CVE-2026-16340), status for CVE-2026-14990 unknown
Affected Release Streams
The following IBM DataPower Gateway releases are affected:
CVE-2026-16340:
10.5.0.0 to 10.5.0.22
10.6.0.0 to 10.6.0.10
10.6.1 to 10.6.6 in release stream 10.6 CD
11.0.0.0 to 11.0.0.2
CVE-2026-14990:
10.6.0.0 to 10.6.0.10
The CVSS vector for CVE-2026-16340 classifies the vulnerability as exploitable over the network. It has a low attack complexity, no required permissions, and no user interaction. Confidentiality, integrity, and availability are each rated with high impact.
Corrected Versions and Timeline
Corrected versions are available for the affected release streams:
Affected Release Stream
Corrected Version
IBM DataPower Gateway 10.5.0
10.5.0.23
IBM DataPower Gateway 10.6.0
10.6.0.11
IBM DataPower Gateway 10.6 CD
10.6.7
IBM DataPower Gateway 11.0.0
11.0.0.3
The fixes for CVE-2026-16340 were available on September 25, 2026 . The CVE publication occurred on October 08, 2026. No active exploitation of CVE-2026-16340 is documented.
CVE-2026-14990: Cross-Site Scripting in Release Stream 10.6.0
IBM DataPower Gateway 10.6.0.0 to 10.6.0.10 is also affected by CVE-2026-14990 a cross-site scripting vulnerability with a CVSS score of 9.3. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. The vulnerability requires user interaction, but allows a remote, unauthenticated attacker to compromise confidentiality and integrity with high impact. The scope is rated as „Changed.“.
The patch status for CVE-2026-14990 is unknown at the time of this article's publication. Organizations using release stream 10.6.0 should consult the IBM Security Advisory and check whether the already available version 10.6.0.11 also addresses CVE-2026-14990 or if another update is necessary.
Prioritization of Remediation
Organizations should first determine if any of the affected release versions are in use. Then, the scheduled corrected version for the respective release stream should be planned and the achieved update status should be verified.
A patch is available for CVE-2026-16340 with version 10.6.0.11. For CVE-2026-14990, it should be verified whether this version also provides a fix or if another update is required.
If an update is not immediately possible, restricting network access to the gateway may be considered as a temporary measure. Additionally, it can be checked whether RFC2047-based inputs from external sources can be filtered or validated. For CVE-2026-14990, inputs that could lead to cross-site scripting should be validated and filtered.
For further management, IBM DataPower Gateway and associated security alerts should be included in ongoing vulnerability and vendor risk monitoring.
IBM DataPower Gateway is used in many industries as a central API and integration gateway — including financial service providers subject to the EU DORA regulation, as well as operators of critical infrastructures in Germany and Austria, for which NIS-2 implementation obligations apply (in Austria via the NISG). Companies in Switzerland are subject to the revised Information Security Act (ISG) with reporting obligations to BACS. If successful exploitation leads to the processing or leakage of personal data, the GDPR reporting obligation under Art. 33 applies with a 72-hour deadline to the responsible supervisory authority.
IBM DataPower Gateway can be operated as an externally reachable service under its own domain. For CVE-2026-16340 and CVE-2026-14990, it is therefore initially relevant which gateways are publicly visible and which software is recognizable there.
LocateRisk supports in External Attack Surface Management in making externally reachable systems and deployed software visible. This visibility can assist in the technical assessment of whether publicly accessible DataPower Gateway instances need to be included in the patch process.
Continuous Vendor Risk Management complements this technical perspective. Security reports from IBM can be included in the assessment of the vendor, while the examination of your own external infrastructure takes place separately.
Am I affected?
This affects IBM DataPower Gateway 10.5.0, IBM DataPower Gateway 10.6.0 and IBM DataPower Gateway 10.6 CD in the versions mentioned above; the corresponding fixed releases are listed in the table above. Those who want to know whether IBM DataPower Gateway 10.5.0, IBM DataPower Gateway 10.6.0 and IBM DataPower Gateway 10.6 CD are visible in their own externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-16340 is a critical security vulnerability in IBM DataPower Gateway with a CVSS score of 9.8. It is based on an Out-of-Bounds Write (CWE-787) in the parser for RFC2047 Encoded-Word inputs and allows a remote, unauthenticated attacker to execute arbitrary code on the affected system.
CVE-2026-14990 is a critical cross-site scripting vulnerability in IBM DataPower Gateway 10.6.0.0 to 10.6.0.10 with a CVSS score of 9.3. It allows a remote, unauthenticated attacker to compromise confidentiality and integrity, but requires user interaction.
The release streams affected for CVE-2026-16340 are 10.5.0.0 to 10.5.0.22, 10.6.0.0 to 10.6.0.10, 10.6.1 to 10.6.6 (10.6 CD), and 11.0.0.0 to 11.0.0.2. The versions affected for CVE-2026-14990 are 10.6.0.0 to 10.6.0.10. IBM provides corrected versions for all four streams: 10.5.0.23, 10.6.0.11, 10.6.7, and 11.0.0.3.
The primary protection consists of timely updates to the respective corrected version. Additionally, it can be checked whether access to the gateway is restricted and whether RFC2047-based inputs from external sources can be filtered while an update is still pending. For CVE-2026-14990, inputs that may lead to cross-site scripting should be validated and filtered.
Status: October 08, 2026. This contribution serves general informational purposes and is not legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-16340
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.