Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Sandboxing Closes the Phishing Detection Visibility Gap
September 23, 2026
Critical cPanel Vulnerability Exposes User Accounts
September 23, 2026
Outerlimit Raises $16M to Secure AI Agents with Zero Trust
September 23, 2026
Home/CyberSecurity News/Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems
CyberSecurity News

Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems

Key Takeaways IBM has released critical security patches for its Financial Transaction Manager (FTM) for Red Hat OpenShift. Multiple severe vulnerabilities, some with CVSS scores up to 9.9, could...

Jennifer sherman
Jennifer sherman
September 23, 2026 3 Min Read
2 0

Key Takeaways

  • IBM has released critical security patches for its Financial Transaction Manager (FTM) for Red Hat OpenShift.
  • Multiple severe vulnerabilities, some with CVSS scores up to 9.9, could enable remote code execution, unauthorized payment actions, and data theft.
  • Versions 4.0.6.0 through 4.0.10.0 of FTM for Red Hat OpenShift are affected.
  • Organizations must upgrade to FTM 4.0.11.0 immediately, as no temporary workarounds exist.

IBM FTM for Red Hat OpenShift Plagued by Critical Flaws

IBM has issued an urgent security bulletin addressing a multitude of vulnerabilities within its Financial Transaction Manager (FTM) for Red Hat OpenShift. These critical flaws, some scoring as high as 9.9 on the CVSS scale, present serious risks, including remote code execution, unauthorized manipulation of payment systems, credential compromise, sensitive data exposure, and service disruptions. The impacted versions span FTM 4.0.6.0 through 4.0.10.0.

Table Of Content

  • Key Takeaways
  • IBM FTM for Red Hat OpenShift Plagued by Critical Flaws
  • Remote Code Execution and Data Compromise Risks
  • Direct Threats to Payment Security
  • What You Should Do

FTM is a cornerstone platform for managing and processing intricate payment workflows within financial institutions. Given its direct handling of payment data, transaction rules, operator sessions, and core business logic, successful exploitation of these vulnerabilities could lead to catastrophic consequences for financial organizations relying on the system.

Remote Code Execution and Data Compromise Risks

Among the most severe issues is CVE-2026-18163, a remote code execution vulnerability rated 9.8 CVSS. This flaw originates from unsafe deserialization of untrusted data, allowing an attacker to exploit it remotely without any authentication or user interaction. By sending a specially crafted serialized payload, an attacker could execute arbitrary code on a vulnerable FTM server.

Another critical vulnerability, CVE-2026-18162, also carries a CVSS score of 9.8. This issue arises from improper handling of user-controlled input within JavaScript’s Function constructor. An unauthenticated remote attacker could leverage this to inject and execute arbitrary code within the affected environment.

IBM also addressed CVE-2026-18169, an extremely critical vulnerability rated 9.9. This flaw involves inadequate validation of symbolic links. An authenticated remote attacker could exploit this to gain unauthorized access to sensitive information, alter data, and potentially undermine the integrity of the entire system. This vulnerability is particularly concerning as even low-level access could be escalated by abusing file system links to access protected files or directories.

Direct Threats to Payment Security

Several other identified vulnerabilities directly imperil the security of financial transactions:

  • CVE-2026-18177: This flaw, stemming from missing authorization checks, could allow an attacker to perform unauthorized payment actions.
  • CVE-2026-18132: Similarly, this vulnerability enables an authenticated remote attacker to modify payment-related data or initiate unauthorized payment mutation actions.
  • CVE-2026-18872: A stored cross-site scripting (XSS) vulnerability, rated 9.3, resides in the FTM user interface’s NetworkAcknowledgement React component. An attacker could inject malicious scripts into stored network acknowledgment data. When an authenticated operator subsequently views this compromised content, the script could execute in their browser, potentially leading to session hijacking and unauthorized operator-level payment actions.

Further vulnerabilities include CVE-2026-17635, rated 9.1, which is caused by incorrect HTTP method-based security constraints. This could permit an unauthenticated remote attacker to perform unauthorized actions. Another 9.1-rated flaw, CVE-2026-17645, allows an authenticated remote user to achieve elevated privileges due to improper privilege management.

Organizations should also prioritize addressing CVE-2026-18137, an ESQL injection vulnerability with a CVSS score of 8.1. Successful exploitation could enable attackers to execute arbitrary ESQL commands, potentially exposing sensitive payment records or altering backend processing logic.

The comprehensive security update also rectifies a host of other issues, including hard-coded cryptographic keys, XML external entity (XXE) injection vulnerabilities, server-side request forgery (SSRF), cleartext data transmission, path traversal, weak authentication mechanisms, missing authorization checks, SQL injection, and denial-of-service vulnerabilities.

Affected FTM for Red Hat OpenShift versions range from 4.0.6.0 through 4.0.10.0. IBM recommends that all organizations immediately update to FTM 4.0.11.0, which incorporates fixes for all reported vulnerabilities. IBM has not provided any temporary workarounds or mitigations, underscoring the critical importance of prompt patching.

What You Should Do

  • Immediately update all instances of IBM Financial Transaction Manager for Red Hat OpenShift to version 4.0.11.0.
  • Review all exposed FTM services and restrict access to management interfaces to authorized personnel only.
  • Actively monitor for unusual transaction changes and operator activity within the FTM environment.
  • Rotate sensitive credentials where appropriate, especially for accounts with access to FTM.
  • Investigate any unusual or suspicious requests targeting payment and business-rule management endpoints.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Ryuk Ransomware Operator Sentenced for Deploying Malware and Extortion

Next Post

Outerlimit Raises $16M to Secure AI Agents with Zero Trust

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
New Malware Uses Evasive Domain Tactics to Hide Infrastructure
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us