Technology · IBM
IBM Concert vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in IBM Concert: 16 in the last 7 days and 18 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6544, was published on 24 September 2026.
- Last 7 days
- 16
- Last 90 days
- 18
- Critical, all time
- 5
- Exploited in the wild
- 0
About IBM Concert
An AI-powered automation platform designed to provide insights and management for business operations and IT infrastructure.
Latest IBM Concert vulnerabilities
- CVE-2026-6544: IBM Concert directory recursion allows uncontrolled file inclusionmediumCVSS 6.2EPSS 0.1%
- CVE-2026-6935: IBM Concert unqualified command invocationhighCVSS 7.8EPSS 0.1%
- CVE-2026-6928: IBM Concert use-after-free memory corruptioncriticalCVSS 9.8EPSS 0.4%
- CVE-2026-6925: IBM Concert directory traversal via malformed URLmediumCVSS 5.3EPSS 0.3%
- CVE-2026-6794: IBM Concert double free in memory managementhighCVSS 7.8EPSS 0.1%
- CVE-2026-6730: IBM Concert buffer overflow in local bounds checkingcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-6721: IBM Concert command injectioncriticalCVSS 9.8EPSS 1.5%
- CVE-2026-6718: IBM Concert improper access control in application filesmediumCVSS 6.2EPSS 0.1%
- CVE-2026-6327: IBM Concert log injection vulnerabilitymediumCVSS 4.3EPSS 0.2%
- CVE-2026-3626: IBM Concert information disclosure via error messagemediumCVSS 5.3EPSS 0.2%
- CVE-2026-17472: IBM Concert unauthorized resource access via RBAC wildcardcriticalCVSS 9.6EPSS 0.3%
- CVE-2026-17465: IBM Concert storage limit denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-16426: IBM Concert server-side request forgerymediumCVSS 6.5EPSS 0.2%
- CVE-2026-15915: IBM Concert information disclosure in build context copyingmediumCVSS 6.2EPSS 0.1%
- CVE-2025-36084: IBM Concert weak cryptographic algorithmmediumCVSS 5.9EPSS 0.2%
- CVE-2025-12767: IBM Concert regular expression denial of servicemediumCVSS 5.3EPSS 0.4%
- CVE-2026-3627: IBM Concert SQL injectioncriticalCVSS 9.1EPSS 0.5%
- CVE-2025-64649: IBM Concert improper certificate validationmediumCVSS 5.9EPSS 0.2%
- CVE-2025-13044: IBM Concert arbitrary file overwrite via predictable temporary filesmediumCVSS 6.2EPSS 0.1%
- CVE-2025-36085: IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an…mediumCVSS 5.4EPSS 0.2%
- CVE-2025-36083: IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to…mediumCVSS 6.2EPSS 0.1%
- CVE-2025-36081: IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log…mediumCVSS 5.3EPSS 0.2%
Most severe IBM Concert vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-6721: IBM Concert command injectioncriticalCVSS 9.8EPSS 1.5%
- CVE-2026-6928: IBM Concert use-after-free memory corruptioncriticalCVSS 9.8EPSS 0.4%
- CVE-2026-6730: IBM Concert buffer overflow in local bounds checkingcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-17472: IBM Concert unauthorized resource access via RBAC wildcardcriticalCVSS 9.6EPSS 0.3%
- CVE-2026-3627: IBM Concert SQL injectioncriticalCVSS 9.1EPSS 0.5%
- CVE-2026-6935: IBM Concert unqualified command invocationhighCVSS 7.8EPSS 0.1%
- CVE-2026-6794: IBM Concert double free in memory managementhighCVSS 7.8EPSS 0.1%
- CVE-2026-17465: IBM Concert storage limit denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2026-16426: IBM Concert server-side request forgerymediumCVSS 6.5EPSS 0.2%
- CVE-2025-13044: IBM Concert arbitrary file overwrite via predictable temporary filesmediumCVSS 6.2EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 2 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 16 | 4 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/concert.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM Concert vulnerabilities", https://junglewise.ai/threats/technologies/concert, 26 September 2026.