CVE-2026-16340 is a critical (CVSS 9.8) out-of-bounds write in IBM DataPower Gateway's RFC2047 encoded-word parser that could let a remote attacker execute arbitrary code.
What Is It
CVE-2026-16340 is an out-of-bounds write (CWE-787) in the RFC2047 encoded-word parser of IBM DataPower Gateway. IBM's description says the flaw "could allow a remote attacker to execute arbitrary code." IBM PSIRT reported it, and NVD published it on October 8, 2026. The NVD record is currently in "Received" status.
Why It Matters
IBM gives the flaw a CVSS 3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That means:
- Network-reachable: an attacker does not need local access.
- Low attack complexity: no special conditions are needed.
- No privileges or user interaction required.
- High impact to confidentiality, integrity, and availability.
DataPower Gateway often sits at the edge of a network to handle API and integration traffic, so a remotely triggerable code-execution bug on it is serious.
Exploitation status: CVE-2026-16340 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation at this time. The supplied sources do not say whether exploitation has been seen in the wild.
What's Vulnerable
According to IBM's affected-product data, these IBM DataPower Gateway releases are affected:
| Product Stream | Affected Versions |
|---|---|
| DataPower Gateway 10.5.0 | 10.5.0.0 through 10.5.0.22 |
| DataPower Gateway 10.6.0 | 10.6.0.0 through 10.6.0.10 |
| DataPower Gateway 10.6CD | 10.6.1 through 10.6.6 |
| DataPower Gateway 11.0.0 | 11.0.0.0 through 11.0.0.2 |
Patch Status
The NVD record links to an IBM support advisory (node 7289775), but the supplied data does not list fixed versions or specific remediation steps. CISA KEV has not set a required action or due date because the CVE is not in the catalog.
Organizations running affected DataPower Gateway versions should read IBM's advisory for fix availability and upgrade guidance. Given the critical severity and unauthenticated network attack vector, they should prioritize patching.