Remote Denial of Service Risk in IBM DataPower Gateway
CVE-2026-16167
7.5HIGH
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16167?
The vulnerability in IBM DataPower Gateway allows remote attackers to exploit improper bounds checking, potentially leading to a denial of service. Affected versions include those ranging from 10.5.0.0 to 11.0.0.2, making it crucial for users to apply the latest patches. Visit IBM's advisory for more details to secure your infrastructure.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6