CVE-2026-18131

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

  • Published Sep 22, 2026
  • CVSS 8.2 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-18131 at the National Vulnerability Database