Out-of-Bounds Write Vulnerability in IBM DataPower Gateway
CVE-2026-15784
8.1HIGH
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-15784?
An out-of-bounds write vulnerability in IBM DataPower Gateway allows remote attackers to execute arbitrary code. Affected versions include 10.5.0.0 to 10.5.0.22, 10.6.1 to 10.6.6, 10.6.0.0 to 10.6.0.10, and 11.0.0.0 to 11.0.0.2. It is crucial for users to apply the latest patches to mitigate potential risks.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6