cbcvebase.
CVE-2025-36375
published 2026-04-01

CVE-2025-36375: IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.17%
6.3th percentile
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Affected

6 ranges
VendorProductVersion rangeFixed in
ibmdatapower_gateway>= 10.5.0.0 < 10.5.0.2110.5.0.21
ibmdatapower_gateway>= 10.6.0.0 < 10.6.0.910.6.0.9
ibmdatapower_gateway>= 10.6.1.0 < 10.6.6.010.6.6.0
ibmdatapower_gateway_10.5.010.5.0.0 – 10.5.0.20
ibmdatapower_gateway_10.6.010.6.0.0 – 10.6.0.8
ibmdatapower_gateway_10.6cd10.6.1.0 – 10.6.5.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.