Heap-Based Buffer Overflow in IBM DataPower Gateway
CVE-2026-14269
9.8CRITICAL
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-14269?
IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are susceptible to a heap-based buffer overflow due to inadequate bounds checking. This vulnerability allows an unauthenticated remote attacker to exploit the buffer overflow, potentially leading to the execution of arbitrary code on the affected system.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6