CVE-2026-78543: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.
Other sources
IBM App Connect Enterprise could allow a remote attacker to cause a denial of service due to an infinite loop.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.29Patch IT49773 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.2Patch IT49773 - Upgrade
Upgrade
IBM Integration Bus for z/OSto a version that resolves this vulnerability.Fixed in 10.1.0.7Patch IT49773
Event History
Frequently Asked Questions
Which IBM products should be prioritized for triage?
Triage IBM App Connect Enterprise and IBM Integration Bus for z/OS.
Does exploitation require an attacker to have local access?
No. The issue is described as remotely exploitable, so systems reachable by a remote attacker should be assessed first.
Can affected or fixed versions be identified from the available record?
No version or fixed-release information is provided in the available data.