Junglewise Threat Intelligence

CVE-2026-18162: IBM Financial Transaction Manager remote code execution in Function constructor

CVE-2026-18162 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is a payment processing and transaction management system used by financial institutions. A remote attacker can execute arbitrary code on the system by supplying specially crafted input that is not properly validated before being used in a Function constructor, allowing complete system compromise.

Technical details

The vulnerability is a code injection flaw in the Function constructor where user-controlled input is not properly sanitized. An unauthenticated remote attacker can craft a malicious request that exploits this improper neutralization to execute arbitrary code with the privileges of the FTM application. Exploitation does not require authentication or user interaction and can be triggered directly over the network.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats