Junglewise Threat Intelligence

CVE-2026-18154: IBM Financial Transaction Manager weak cryptographic key

CVE-2026-18154 · Severity: high · CVSS 8 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM), a financial transaction processing platform for OpenShift environments, uses hard-coded or predictable cryptographic keys to protect sensitive data. A remote attacker can exploit this weakness to decrypt communications and extract confidential financial information without authentication.

Technical details

The vulnerability stems from use of hard-coded or predictable cryptographic keys in IBM FTM, allowing a remote unauthenticated attacker to obtain sensitive information through cryptographic attacks. The attack is network-accessible and requires no authentication, user interaction, or special conditions. An attacker gaining knowledge of or predicting the key material can decrypt sensitive data and forge authentication tokens.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats