CVE-2026-78543: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
Other sources
IBM App Connect Enterprise could allow a remote attacker to cause a denial of service due to an infinite loop.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterprise 12to a version that resolves this vulnerability.Fixed in 12.0.12.29 - Upgrade
Upgrade
IBM App Connect Enterprise 13to a version that resolves this vulnerability.Fixed in 13.0.8.2 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Patch IT49773
Event History
Frequently Asked Questions
Which IBM products should be prioritized for triage?
Triage IBM App Connect Enterprise and IBM Integration Bus for z/OS.
Does exploitation require an attacker to have local access?
No. The issue is described as remotely exploitable, so systems reachable by a remote attacker should be assessed first.
Can affected or fixed versions be identified from the available record?
No version or fixed-release information is provided in the available data.