Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-16340 2026-10-08

IBM DataPower Gateway CVE-2026-16340: Critical Out-of-Bounds Write in RFC2047 Parser

"CVE-2026-16340 is a critical (CVSS 9.8) out-of-bounds write in IBM DataPower Gateway's RFC2047 encoded-word parser that could let a remote attacker execute arbitrary code."

CVE-2026-16340 is a critical (CVSS 9.8) out-of-bounds write in IBM DataPower Gateway's RFC2047 encoded-word parser that could let a remote attacker execute arbitrary code.

What Is It

CVE-2026-16340 is an out-of-bounds write (CWE-787) in the RFC2047 encoded-word parser of IBM DataPower Gateway. IBM's description says the flaw "could allow a remote attacker to execute arbitrary code." IBM PSIRT reported it, and NVD published it on October 8, 2026. The NVD record is currently in "Received" status.

Why It Matters

IBM gives the flaw a CVSS 3.1 base score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That means:

DataPower Gateway often sits at the edge of a network to handle API and integration traffic, so a remotely triggerable code-execution bug on it is serious.

Exploitation status: CVE-2026-16340 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation at this time. The supplied sources do not say whether exploitation has been seen in the wild.

What's Vulnerable

According to IBM's affected-product data, these IBM DataPower Gateway releases are affected:

Product Stream Affected Versions
DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 through 10.6.6
DataPower Gateway 11.0.0 11.0.0.0 through 11.0.0.2

Patch Status

The NVD record links to an IBM support advisory (node 7289775), but the supplied data does not list fixed versions or specific remediation steps. CISA KEV has not set a required action or due date because the CVE is not in the catalog.

Organizations running affected DataPower Gateway versions should read IBM's advisory for fix availability and upgrade guidance. Given the critical severity and unauthenticated network attack vector, they should prioritize patching.

Sources