PT-2026-107940 · Ibm · Datapower Gateway

CVE-2026-16340

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22 IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 IBM DataPower Gateway versions 10.6.1 through 10.6.6 IBM DataPower Gateway versions 11.0.0.0 through 11.0.0.2
Description A remote attacker can execute arbitrary code due to an out-of-bounds write, which occurs when the system processes data using the RFC2047 encoded-word parser. An out-of-bounds write is a memory corruption error where data is written outside the intended boundary of a buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16340

Affected Products

Datapower Gateway