Junglewise Threat Intelligence

CVE-2026-18095: IBM Financial Transaction Manager buffer overflow

CVE-2026-18095 · Severity: high · CVSS 8.5 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM), a financial processing platform used by enterprises to manage payment transactions, contains a buffer overflow vulnerability that allows an authenticated remote attacker to execute arbitrary code on the system. Exploitation could lead to complete compromise of the financial transaction processing system, enabling theft of transaction data, unauthorized payments, or denial of service.

Technical details

A buffer overflow exists in IBM FTM that allows a remote authenticated attacker to execute arbitrary code. The vulnerability requires valid authentication credentials to exploit. Successful exploitation results in arbitrary code execution with the privileges of the affected service.

Affected products

  • IBM Financial Transaction Manager <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats