Executive brief
IBM Financial Transaction Manager (FTM) is a transaction processing platform used by financial institutions for payment and settlement operations. A remote attacker can trigger a denial of service by sending requests that allocate system resources without limits, disrupting transaction processing and causing service unavailability for customers and clients.
Technical details
CVE-2026-18170 is an unauthenticated network-accessible denial of service vulnerability in IBM FTM caused by unbounded resource allocation without throttling or rate limiting. An attacker can exploit this by sending crafted requests that exhaust memory, CPU, or connection resources, causing the application to become unresponsive. The vulnerability requires network access but no authentication or user interaction.
Affected products
- IBM Financial Transaction Manager 4.x and possibly others
Timeline
- 2026-09-22: disclosed