{"schema_version":1,"title":"IBM Concert vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in IBM Concert: 16 in the last 7 days and 18 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6544, was published on 24 September 2026.","url":"https://junglewise.ai/threats/technologies/concert","json_url":"https://junglewise.ai/threats/technologies/concert.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/concert","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":22,"critical":5,"exploited":0,"last_7_days":16,"last_30_days":18,"last_90_days":18,"last_365_days":22},"latest":[{"cve":"CVE-2026-6544","cvss":6.2,"epss":0.0012,"slug":"cve-2026-6544-ibm-concert-1-0-0-through-3-0-0-allows-recursive-copying-of","title":"IBM Concert directory recursion allows uncontrolled file inclusion","severity":"medium","exploited":false,"published_at":"2026-09-24T15:17:30.89+00:00","url":"https://junglewise.ai/threats/cve-2026-6544-ibm-concert-1-0-0-through-3-0-0-allows-recursive-copying-of"},{"cve":"CVE-2026-6935","cvss":7.8,"epss":0.0012,"slug":"cve-2026-6935-ibm-concert-1-0-0-through-3-0-0-invokes-operating-system-commands","title":"IBM Concert unqualified command invocation","severity":"high","exploited":false,"published_at":"2026-09-23T21:17:02.553+00:00","url":"https://junglewise.ai/threats/cve-2026-6935-ibm-concert-1-0-0-through-3-0-0-invokes-operating-system-commands"},{"cve":"CVE-2026-6928","cvss":9.8,"epss":0.0045,"slug":"cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory","title":"IBM Concert use-after-free memory corruption","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.43+00:00","url":"https://junglewise.ai/threats/cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory"},{"cve":"CVE-2026-6925","cvss":5.3,"epss":0.0033,"slug":"cve-2026-6925-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to","title":"IBM Concert directory traversal via malformed URL","severity":"medium","exploited":false,"published_at":"2026-09-23T21:17:02.303+00:00","url":"https://junglewise.ai/threats/cve-2026-6925-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to"},{"cve":"CVE-2026-6794","cvss":7.8,"epss":0.0011,"slug":"cve-2026-6794-ibm-concert-1-0-0-through-3-0-0-has-a-double-free-vulnerability","title":"IBM Concert double free in memory management","severity":"high","exploited":false,"published_at":"2026-09-23T21:17:02.177+00:00","url":"https://junglewise.ai/threats/cve-2026-6794-ibm-concert-1-0-0-through-3-0-0-has-a-double-free-vulnerability"},{"cve":"CVE-2026-6730","cvss":9.8,"epss":0.0044,"slug":"cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow","title":"IBM Concert buffer overflow in local bounds checking","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.053+00:00","url":"https://junglewise.ai/threats/cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow"},{"cve":"CVE-2026-6721","cvss":9.8,"epss":0.0145,"slug":"cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote","title":"IBM Concert command injection","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:01.927+00:00","url":"https://junglewise.ai/threats/cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote"},{"cve":"CVE-2026-6718","cvss":6.2,"epss":0.001,"slug":"cve-2026-6718-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-improper-access","title":"IBM Concert improper access control in application files","severity":"medium","exploited":false,"published_at":"2026-09-23T21:17:01.803+00:00","url":"https://junglewise.ai/threats/cve-2026-6718-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-improper-access"},{"cve":"CVE-2026-6327","cvss":4.3,"epss":0.0017,"slug":"cve-2026-6327-ibm-concert-1-0-0-through-3-0-0-could-allow-an-unauthorized-user","title":"IBM Concert log injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:43.947+00:00","url":"https://junglewise.ai/threats/cve-2026-6327-ibm-concert-1-0-0-through-3-0-0-could-allow-an-unauthorized-user"},{"cve":"CVE-2026-3626","cvss":5.3,"epss":0.0024,"slug":"cve-2026-3626-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to","title":"IBM Concert information disclosure via error message","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:43.157+00:00","url":"https://junglewise.ai/threats/cve-2026-3626-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to"},{"cve":"CVE-2026-17472","cvss":9.6,"epss":0.003,"slug":"cve-2026-17472-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote","title":"IBM Concert unauthorized resource access via RBAC wildcard","severity":"critical","exploited":false,"published_at":"2026-09-22T22:17:07.683+00:00","url":"https://junglewise.ai/threats/cve-2026-17472-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote"},{"cve":"CVE-2026-17465","cvss":6.5,"epss":0.0028,"slug":"cve-2026-17465-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote","title":"IBM Concert storage limit denial of service","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:07.547+00:00","url":"https://junglewise.ai/threats/cve-2026-17465-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote"},{"cve":"CVE-2026-16426","cvss":6.5,"epss":0.0019,"slug":"cve-2026-16426-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-server-side","title":"IBM Concert server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:06.797+00:00","url":"https://junglewise.ai/threats/cve-2026-16426-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-server-side"},{"cve":"CVE-2026-15915","cvss":6.2,"epss":0.0012,"slug":"cve-2026-15915-ibm-concert-1-0-0-through-3-0-0-could-allow-a-local-attacker-to","title":"IBM Concert information disclosure in build context copying","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:06.47+00:00","url":"https://junglewise.ai/threats/cve-2026-15915-ibm-concert-1-0-0-through-3-0-0-could-allow-a-local-attacker-to"},{"cve":"CVE-2025-36084","cvss":5.9,"epss":0.0016,"slug":"cve-2025-36084-ibm-concert-1-0-0-through-3-0-0-uses-weaker-than-expected","title":"IBM Concert weak cryptographic algorithm","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:06.32+00:00","url":"https://junglewise.ai/threats/cve-2025-36084-ibm-concert-1-0-0-through-3-0-0-uses-weaker-than-expected"},{"cve":"CVE-2025-12767","cvss":5.3,"epss":0.0036,"slug":"cve-2025-12767-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to","title":"IBM Concert regular expression denial of service","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:05.467+00:00","url":"https://junglewise.ai/threats/cve-2025-12767-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote-attacker-to"},{"cve":"CVE-2026-3627","cvss":9.1,"epss":0.0051,"slug":"cve-2026-3627-ibm-concert-sql-injection","title":"IBM Concert SQL injection","severity":"critical","exploited":false,"published_at":"2026-08-28T22:16:49.063+00:00","url":"https://junglewise.ai/threats/cve-2026-3627-ibm-concert-sql-injection"},{"cve":"CVE-2025-64649","cvss":5.9,"epss":0.0017,"slug":"cve-2025-64649-ibm-concert-improper-certificate-validation","title":"IBM Concert improper certificate validation","severity":"medium","exploited":false,"published_at":"2026-08-28T22:16:45.913+00:00","url":"https://junglewise.ai/threats/cve-2025-64649-ibm-concert-improper-certificate-validation"},{"cve":"CVE-2025-13044","cvss":6.2,"epss":0.0014,"slug":"cve-2025-13044-ibm-concert-arbitrary-file-overwrite-via-predictable-temporary","title":"IBM Concert arbitrary file overwrite via predictable temporary files","severity":"medium","exploited":false,"published_at":"2026-04-07T02:16:15.343+00:00","url":"https://junglewise.ai/threats/cve-2025-13044-ibm-concert-arbitrary-file-overwrite-via-predictable-temporary"},{"cve":"CVE-2025-36085","cvss":5.4,"epss":0.0016,"slug":"cve-2025-36085-ibm-concert-1-0-0-through-2-0-0-software-is-vulnerable-to-server","title":"IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to se","severity":"medium","exploited":false,"published_at":"2025-10-28T15:16:12.577+00:00","url":"https://junglewise.ai/threats/cve-2025-36085-ibm-concert-1-0-0-through-2-0-0-software-is-vulnerable-to-server"},{"cve":"CVE-2025-36083","cvss":6.2,"epss":0.0012,"slug":"cve-2025-36083-ibm-concert-software-1-0-0-through-2-0-0-could-allow-a-local-user","title":"IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of","severity":"medium","exploited":false,"published_at":"2025-10-28T15:16:12.427+00:00","url":"https://junglewise.ai/threats/cve-2025-36083-ibm-concert-software-1-0-0-through-2-0-0-could-allow-a-local-user"},{"cve":"CVE-2025-36081","cvss":5.3,"epss":0.0022,"slug":"cve-2025-36081-ibm-concert-software-1-0-0-through-2-0-0-could-allow-a-user-to","title":"IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.","severity":"medium","exploited":false,"published_at":"2025-10-28T15:16:12.27+00:00","url":"https://junglewise.ai/threats/cve-2025-36081-ibm-concert-software-1-0-0-through-2-0-0-could-allow-a-user-to"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":4,"exploited":0,"vulnerabilities":16}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"},{"name":"IBM Db2","slug":"db2","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/db2"},{"name":"IBM Mq","slug":"mq","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM Verify Identity Access","slug":"verify-identity-access","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/verify-identity-access"}],"technology":{"hub":true,"name":"IBM Concert","slug":"concert","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"software-suite","homepage":"https://www.ibm.com/products/concert","repo_url":"https://www.ibm.com/products/concert","description":"An AI-powered automation platform designed to provide insights and management for business operations and IT infrastructure.","url":"https://junglewise.ai/threats/technologies/concert"},"most_severe":[{"cve":"CVE-2026-6721","cvss":9.8,"epss":0.0145,"slug":"cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote","title":"IBM Concert command injection","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:01.927+00:00","url":"https://junglewise.ai/threats/cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote"},{"cve":"CVE-2026-6928","cvss":9.8,"epss":0.0045,"slug":"cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory","title":"IBM Concert use-after-free memory corruption","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.43+00:00","url":"https://junglewise.ai/threats/cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory"},{"cve":"CVE-2026-6730","cvss":9.8,"epss":0.0044,"slug":"cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow","title":"IBM Concert buffer overflow in local bounds checking","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.053+00:00","url":"https://junglewise.ai/threats/cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow"},{"cve":"CVE-2026-17472","cvss":9.6,"epss":0.003,"slug":"cve-2026-17472-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote","title":"IBM Concert unauthorized resource access via RBAC wildcard","severity":"critical","exploited":false,"published_at":"2026-09-22T22:17:07.683+00:00","url":"https://junglewise.ai/threats/cve-2026-17472-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote"},{"cve":"CVE-2026-3627","cvss":9.1,"epss":0.0051,"slug":"cve-2026-3627-ibm-concert-sql-injection","title":"IBM Concert SQL injection","severity":"critical","exploited":false,"published_at":"2026-08-28T22:16:49.063+00:00","url":"https://junglewise.ai/threats/cve-2026-3627-ibm-concert-sql-injection"},{"cve":"CVE-2026-6935","cvss":7.8,"epss":0.0012,"slug":"cve-2026-6935-ibm-concert-1-0-0-through-3-0-0-invokes-operating-system-commands","title":"IBM Concert unqualified command invocation","severity":"high","exploited":false,"published_at":"2026-09-23T21:17:02.553+00:00","url":"https://junglewise.ai/threats/cve-2026-6935-ibm-concert-1-0-0-through-3-0-0-invokes-operating-system-commands"},{"cve":"CVE-2026-6794","cvss":7.8,"epss":0.0011,"slug":"cve-2026-6794-ibm-concert-1-0-0-through-3-0-0-has-a-double-free-vulnerability","title":"IBM Concert double free in memory management","severity":"high","exploited":false,"published_at":"2026-09-23T21:17:02.177+00:00","url":"https://junglewise.ai/threats/cve-2026-6794-ibm-concert-1-0-0-through-3-0-0-has-a-double-free-vulnerability"},{"cve":"CVE-2026-17465","cvss":6.5,"epss":0.0028,"slug":"cve-2026-17465-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote","title":"IBM Concert storage limit denial of service","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:07.547+00:00","url":"https://junglewise.ai/threats/cve-2026-17465-ibm-concert-1-0-0-through-3-0-0-could-allow-a-remote"},{"cve":"CVE-2026-16426","cvss":6.5,"epss":0.0019,"slug":"cve-2026-16426-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-server-side","title":"IBM Concert server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:06.797+00:00","url":"https://junglewise.ai/threats/cve-2026-16426-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-server-side"},{"cve":"CVE-2025-13044","cvss":6.2,"epss":0.0014,"slug":"cve-2025-13044-ibm-concert-arbitrary-file-overwrite-via-predictable-temporary","title":"IBM Concert arbitrary file overwrite via predictable temporary files","severity":"medium","exploited":false,"published_at":"2026-04-07T02:16:15.343+00:00","url":"https://junglewise.ai/threats/cve-2025-13044-ibm-concert-arbitrary-file-overwrite-via-predictable-temporary"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}