Junglewise Threat Intelligence

CVE-2026-18176: IBM Financial Transaction Manager cleartext transmission of sensitive information

CVE-2026-18176 · Severity: high · CVSS 7.4 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager (FTM) is enterprise software that manages payment transactions and financial operations. A vulnerability allows remote attackers to intercept and read sensitive information transmitted without encryption, potentially exposing credentials, payment details, and other confidential data.

Technical details

The vulnerability stems from cleartext transmission of sensitive information in IBM FTM, allowing network-adjacent or remote attackers to passively intercept communications without authentication. An attacker positioned to observe network traffic can extract sensitive data including credentials and transaction details. The vulnerability is remotely exploitable over the network.

Affected products

  • IBM Financial Transaction Manager

Timeline

  • 2026-09-22: disclosed

References

Related threats