CVE-2026-17646

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

  • Published Sep 22, 2026
  • CVSS 8.5 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-17646 at the National Vulnerability Database