cbcvebase.
CVE-2026-12730
published 2026-08-05

CVE-2026-12730: IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0…

PriorityP414low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.10%
1.1th percentile
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
ibmbusiness_automation_workflow——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.