IBM has disclosed CVE-2026-14992, a critical (CVSS 9.8) buffer overflow in several IBM DataPower Gateway release lines that is network-reachable and needs no authentication or user interaction.
What Is It
CVE-2026-14992 is a buffer overflow vulnerability in IBM DataPower Gateway, classified as CWE-787 (Out-of-bounds Write). IBM PSIRT published it on 2026-10-08. The NVD record is in "Awaiting Analysis" status, so NVD has not finished its own enrichment. The public description doesn't name the vulnerable component or the trigger condition.
Why It Matters
IBM gives the flaw a CVSS v3.1 base score of 9.8 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice:
- Attack vector: Network
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Impact: High to confidentiality, integrity, and availability
As of publication, CVE-2026-14992 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. Even so, an unauthenticated, network-reachable flaw with high impact to confidentiality, integrity, and availability deserves a high place in patch queues.
What's Vulnerable
According to IBM, these IBM DataPower Gateway versions are affected:
| Product line | Affected versions |
|---|---|
| DataPower Gateway 10.5.0 | 10.5.0.0 through 10.5.0.22 |
| DataPower Gateway 10.6.0 | 10.6.0.0 through 10.6.0.10 |
| DataPower Gateway 10.6CD | 10.6.1 through 10.6.6 |
| DataPower Gateway 11.0.0 | 11.0.0.0 through 11.0.0.2 |
Patch Status
The source data doesn't list fixed versions. IBM's security bulletin, linked below, is the authoritative source for fix and upgrade guidance. No CISA KEV remediation deadline or required action applies, because the CVE is not listed in the CISA KEV catalog as of publication.
Organizations running affected DataPower Gateway versions should:
- Review the IBM bulletin and apply the fixes it gives.
- Check that DataPower management and service interfaces are reachable only from networks that need them.
Sources
- IBM Security Bulletin: https://www.ibm.com/support/pages/node/7289775
- NVD entry for CVE-2026-14992: https://nvd.nist.gov/vuln/detail/CVE-2026-14992
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog