{"schema_version":1,"title":"IBM Financial Transaction Manager vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 45 vulnerabilities in IBM Financial Transaction Manager: 45 in the last 7 days and 45 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93030, was published on 25 September 2026.","url":"https://junglewise.ai/threats/technologies/financial-transaction-manager","json_url":"https://junglewise.ai/threats/technologies/financial-transaction-manager.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/financial-transaction-manager","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":24,"all_time":45,"critical":6,"exploited":0,"last_7_days":45,"last_30_days":45,"last_90_days":45,"last_365_days":45},"latest":[{"cve":"CVE-2026-93030","cvss":6.5,"slug":"cve-2026-93030-ftm-4-x-all-could-allow-a-remote-authenticated-attacker-to-obtain","title":"IBM Financial Transaction Manager XML external entity injection","severity":"medium","exploited":false,"published_at":"2026-09-25T15:17:56.81+00:00","url":"https://junglewise.ai/threats/cve-2026-93030-ftm-4-x-all-could-allow-a-remote-authenticated-attacker-to-obtain"},{"cve":"CVE-2026-19267","cvss":6.2,"epss":0.0013,"slug":"cve-2026-19267-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager missing authentication in Business Rules Manager","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:42.237+00:00","url":"https://junglewise.ai/threats/cve-2026-19267-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-19179","cvss":8.2,"epss":0.003,"slug":"cve-2026-19179-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager boolean-based SQL injection","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:42.107+00:00","url":"https://junglewise.ai/threats/cve-2026-19179-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-19087","cvss":4.4,"epss":0.0009,"slug":"cve-2026-19087-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager privilege escalation in container","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:41.98+00:00","url":"https://junglewise.ai/threats/cve-2026-19087-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18875","cvss":7.3,"epss":0.0022,"slug":"cve-2026-18875-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager RAG poisoning via unauthenticated runbook","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.85+00:00","url":"https://junglewise.ai/threats/cve-2026-18875-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-18872","cvss":9.3,"epss":0.0019,"slug":"cve-2026-18872-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager stored cross-site scripting in UI","severity":"critical","exploited":false,"published_at":"2026-09-23T16:16:41.72+00:00","url":"https://junglewise.ai/threats/cve-2026-18872-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-18505","cvss":5.4,"epss":0.0015,"slug":"cve-2026-18505-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager open redirect in HostHeaderFilter","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:41.59+00:00","url":"https://junglewise.ai/threats/cve-2026-18505-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-18490","cvss":8.8,"epss":0.0025,"slug":"cve-2026-18490-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager RCE via Java deserialization","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.46+00:00","url":"https://junglewise.ai/threats/cve-2026-18490-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-18185","cvss":7.3,"epss":0.0026,"slug":"cve-2026-18185-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager missing authentication for critical function","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.337+00:00","url":"https://junglewise.ai/threats/cve-2026-18185-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18184","cvss":7.4,"epss":0.0022,"slug":"cve-2026-18184-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager XXE injection","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.21+00:00","url":"https://junglewise.ai/threats/cve-2026-18184-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18181","cvss":8.1,"epss":0.0025,"slug":"cve-2026-18181-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager authentication bypass via hardcoded key","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.083+00:00","url":"https://junglewise.ai/threats/cve-2026-18181-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18180","cvss":6.5,"epss":0.0027,"slug":"cve-2026-18180-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager SQL injection","severity":"medium","exploited":false,"published_at":"2026-09-23T16:16:40.957+00:00","url":"https://junglewise.ai/threats/cve-2026-18180-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18179","cvss":6.5,"epss":0.0024,"slug":"cve-2026-18179-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager missing authorization in chat sessions","severity":"medium","exploited":false,"published_at":"2026-09-23T14:17:07.783+00:00","url":"https://junglewise.ai/threats/cve-2026-18179-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18177","cvss":7.1,"epss":0.0018,"slug":"cve-2026-18177-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager missing authorization in payment execution","severity":"high","exploited":false,"published_at":"2026-09-23T14:17:07.66+00:00","url":"https://junglewise.ai/threats/cve-2026-18177-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18176","cvss":7.4,"epss":0.0013,"slug":"cve-2026-18176-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager cleartext transmission of sensitive information","severity":"high","exploited":false,"published_at":"2026-09-22T23:17:07.273+00:00","url":"https://junglewise.ai/threats/cve-2026-18176-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18172","cvss":7.4,"epss":0.002,"slug":"cve-2026-18172-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager XXE information disclosure","severity":"high","exploited":false,"published_at":"2026-09-22T23:17:06.993+00:00","url":"https://junglewise.ai/threats/cve-2026-18172-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18170","cvss":6.5,"epss":0.0019,"slug":"cve-2026-18170-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager resource exhaustion denial of service","severity":"medium","exploited":false,"published_at":"2026-09-22T23:17:06.863+00:00","url":"https://junglewise.ai/threats/cve-2026-18170-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18169","cvss":9.9,"epss":0.0053,"slug":"cve-2026-18169-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager symbolic link validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.73+00:00","url":"https://junglewise.ai/threats/cve-2026-18169-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18163","cvss":9.8,"epss":0.0051,"slug":"cve-2026-18163-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager arbitrary code execution via deserialization","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.6+00:00","url":"https://junglewise.ai/threats/cve-2026-18163-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18162","cvss":9.8,"epss":0.0048,"slug":"cve-2026-18162-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager remote code execution in Function constructor","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.463+00:00","url":"https://junglewise.ai/threats/cve-2026-18162-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18161","cvss":4.3,"epss":0.002,"slug":"cve-2026-18161-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager audit log falsification via HTTP header validation","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:11.1+00:00","url":"https://junglewise.ai/threats/cve-2026-18161-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18156","cvss":6.5,"epss":0.0024,"slug":"cve-2026-18156-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager authorization bypass via identity forgery","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:10.973+00:00","url":"https://junglewise.ai/threats/cve-2026-18156-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18154","cvss":8,"epss":0.0017,"slug":"cve-2026-18154-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager weak cryptographic key","severity":"high","exploited":false,"published_at":"2026-09-22T22:17:10.83+00:00","url":"https://junglewise.ai/threats/cve-2026-18154-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18153","cvss":5.4,"epss":0.0014,"slug":"cve-2026-18153-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager hardcoded cryptographic keys","severity":"medium","exploited":false,"published_at":"2026-09-22T22:17:10.693+00:00","url":"https://junglewise.ai/threats/cve-2026-18153-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18152","cvss":7.4,"epss":0.0012,"slug":"cve-2026-18152-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager cryptographic signature verification bypass","severity":"high","exploited":false,"published_at":"2026-09-22T22:17:10.563+00:00","url":"https://junglewise.ai/threats/cve-2026-18152-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":6,"exploited":0,"vulnerabilities":45},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM Guardium Data Protection","slug":"guardium-data-protection","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/guardium-data-protection"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Concert","slug":"concert","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/concert"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM Mq","slug":"mq","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"}],"technology":{"hub":true,"name":"IBM Financial Transaction Manager","slug":"financial-transaction-manager","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"financial-transaction-processing","description":"IBM financial transaction processing system for managing payment and fund transfer operations.","url":"https://junglewise.ai/threats/technologies/financial-transaction-manager"},"most_severe":[{"cve":"CVE-2026-18169","cvss":9.9,"epss":0.0053,"slug":"cve-2026-18169-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager symbolic link validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.73+00:00","url":"https://junglewise.ai/threats/cve-2026-18169-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18163","cvss":9.8,"epss":0.0051,"slug":"cve-2026-18163-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager arbitrary code execution via deserialization","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.6+00:00","url":"https://junglewise.ai/threats/cve-2026-18163-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18162","cvss":9.8,"epss":0.0048,"slug":"cve-2026-18162-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager remote code execution in Function constructor","severity":"critical","exploited":false,"published_at":"2026-09-22T23:17:06.463+00:00","url":"https://junglewise.ai/threats/cve-2026-18162-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18872","cvss":9.3,"epss":0.0019,"slug":"cve-2026-18872-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager stored cross-site scripting in UI","severity":"critical","exploited":false,"published_at":"2026-09-23T16:16:41.72+00:00","url":"https://junglewise.ai/threats/cve-2026-18872-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-17645","cvss":9.1,"epss":0.0038,"slug":"cve-2026-17645-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-22T22:17:08.73+00:00","url":"https://junglewise.ai/threats/cve-2026-17645-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-17635","cvss":9.1,"epss":0.0035,"slug":"cve-2026-17635-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager improper HTTP security constraints","severity":"critical","exploited":false,"published_at":"2026-09-22T22:17:08.077+00:00","url":"https://junglewise.ai/threats/cve-2026-17635-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-17636","cvss":8.8,"epss":0.005,"slug":"cve-2026-17636-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager remote code execution via improper validation","severity":"high","exploited":false,"published_at":"2026-09-22T22:17:08.207+00:00","url":"https://junglewise.ai/threats/cve-2026-17636-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-18490","cvss":8.8,"epss":0.0025,"slug":"cve-2026-18490-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is","title":"IBM Financial Transaction Manager RCE via Java deserialization","severity":"high","exploited":false,"published_at":"2026-09-23T16:16:41.46+00:00","url":"https://junglewise.ai/threats/cve-2026-18490-ibm-financial-transaction-manager-ftm-for-redhat-openshift-is"},{"cve":"CVE-2026-17647","cvss":8.8,"epss":0.0022,"slug":"cve-2026-17647-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager command execution from untrusted control","severity":"high","exploited":false,"published_at":"2026-09-22T22:17:08.983+00:00","url":"https://junglewise.ai/threats/cve-2026-17647-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"},{"cve":"CVE-2026-17644","cvss":8.8,"epss":0.001,"slug":"cve-2026-17644-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could","title":"IBM Financial Transaction Manager hard-coded credentials local escalation","severity":"high","exploited":false,"published_at":"2026-09-22T22:17:08.597+00:00","url":"https://junglewise.ai/threats/cve-2026-17644-ibm-financial-transaction-manager-ftm-for-redhat-openshift-could"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}