Arbitrary Code Execution Vulnerability in IBM DataPower Gateway
CVE-2026-16340
9.8CRITICAL
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16340?
A vulnerability in the IBM DataPower Gateway allows a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser. This issue affects multiple versions of the product, making it critical for users to apply all relevant patches to mitigate the risk of exploitation.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6