Remote Code Execution Vulnerability in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18162
9.8CRITICAL
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-18162?
A security vulnerability exists in IBM Financial Transaction Manager for RedHat OpenShift that permits a remote attacker to execute arbitrary code. This flaw arises from the inadequate handling of user-controlled input within the Function constructor, potentially leading to significant security risks. It is essential for users of the product to apply the necessary patches provided by IBM to mitigate this vulnerability and safeguard their systems.
Affected Version(s)
Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064