cbcvebase.
CVE-2026-9074
published 2026-07-08

CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.28%
20.4th percentile
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmapi_connect
ibmapi_connect>= 10.0.8.0 < 10.0.8.910.0.8.9
ibmapi_connect>= 10.0.8.0 < 10.0.8.1010.0.8.10
ibmapi_connect>= 12.1.0.0 < 12.1.1.012.1.1.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.