Junglewise Threat Intelligence

CVE-2026-18153: IBM Financial Transaction Manager hardcoded cryptographic keys

CVE-2026-18153 · Severity: medium · CVSS 5.4 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager is middleware that processes financial transactions in enterprise environments. An authenticated attacker can exploit hardcoded cryptographic keys and initialization vectors to forge authentication tags and decrypt sensitive transaction data, compromising the integrity and confidentiality of financial operations.

Technical details

This vulnerability stems from the use of hardcoded cryptographic keys and initialization vectors in FTM's authentication mechanism (CWE-327). An authenticated network attacker can leverage these static credentials to forge authentication tags and obtain sensitive information without user interaction. A fix is available from IBM.

Affected products

  • IBM Financial Transaction Manager 4.x

Timeline

  • 2026-09-22: disclosed

References

Related threats