cbcvebase.
CVE-2026-14979
published 2026-07-17

CVE-2026-14979: IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0…

PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.36%
28.3th percentile
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmengineering_lifecycle_management
ibmengineering_lifecycle_management7.0.3 ( Interim Fix 001 – ) Interim Fix 021
ibmengineering_lifecycle_management7.1.0 ( Interim Fix 001 – ) Interim Fix 009
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.