Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-14992 2026-10-08

Critical Buffer Overflow in IBM DataPower Gateway (CVE-2026-14992)

"IBM has disclosed CVE-2026-14992, a critical (CVSS 9.8) buffer overflow in several IBM DataPower Gateway release lines that is network-reachable and needs no authentication or user interaction."

IBM has disclosed CVE-2026-14992, a critical (CVSS 9.8) buffer overflow in several IBM DataPower Gateway release lines that is network-reachable and needs no authentication or user interaction.

What Is It

CVE-2026-14992 is a buffer overflow vulnerability in IBM DataPower Gateway, classified as CWE-787 (Out-of-bounds Write). IBM PSIRT published it on 2026-10-08. The NVD record is in "Awaiting Analysis" status, so NVD has not finished its own enrichment. The public description doesn't name the vulnerable component or the trigger condition.

Why It Matters

IBM gives the flaw a CVSS v3.1 base score of 9.8 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice:

As of publication, CVE-2026-14992 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. Even so, an unauthenticated, network-reachable flaw with high impact to confidentiality, integrity, and availability deserves a high place in patch queues.

What's Vulnerable

According to IBM, these IBM DataPower Gateway versions are affected:

Product line Affected versions
DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 through 10.6.6
DataPower Gateway 11.0.0 11.0.0.0 through 11.0.0.2

Patch Status

The source data doesn't list fixed versions. IBM's security bulletin, linked below, is the authoritative source for fix and upgrade guidance. No CISA KEV remediation deadline or required action applies, because the CVE is not listed in the CISA KEV catalog as of publication.

Organizations running affected DataPower Gateway versions should:

Sources