Our takeIBM App Connect Enterprise has multiple high-severity flaws that let attackers run arbitrary code, disclose information or manipulate files. This is enterprise estate — patch on your normal cycle. Most smaller shops don't run IBM middleware and can skip this one.Cyber Resilience desk
Sources (5)
What this means for you — Security leader:CERT-Bund flags high-severity flaws in IBM App Connect Enterprise (code execution, info disclosure, file manipulation) plus SQLite, and medium issues in AutoCAD, drawio, and nmap. Prioritize ACE and any in-house SQLite-dependent apps on your normal patch cycle; treat AutoCAD as relevant where design estates run it.
What this means for you — Lean IT orgs:IBM App Connect Enterprise and AutoCAD are enterprise/design tools most lean-IT shops do not run — you can ignore those unless a vendor you depend on does. If you ship or host something that embeds SQLite, apply its updates; drawio XSS and nmap DoS matter only if you expose those yourself.
What this means for you — MSP:Inventory clients for IBM App Connect Enterprise first (high). SQLite shows up embedded across many stacks — push updates where you maintain the app; AutoCAD for design/engineering tenants; drawio and nmap only where you operate them.
What this means for you — Researcher:CERT-Bund WID-SEC-2026-2580–2584: high on IBM ACE and SQLite (RCE/info-disclosure paths), medium on AutoCAD, drawio XSS, and nmap DoS. ACE and SQLite are the ones worth pulling for exploitability and attack surface detail.