Memory Corruption Vulnerability in IBM DataPower Gateway
CVE-2026-16163
8.6HIGH
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16163?
A memory corruption vulnerability exists in the IBM DataPower Gateway due to an out-of-bounds write. This flaw can be exploited by an attacker to manipulate memory allocation and could lead to unauthorized access or denial of service. Affected versions include multiple builds within the 10.5.x, 10.6.x, and 11.0.x series, emphasizing the need for users to apply relevant patches and updates from the vendor promptly to mitigate potential risks.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6