Cyber Resilience
← All news
Confirmed

IBM security advisory (AV26-922)

Our takeIBM MQ and Langflow have multiple confirmed flaws; patch on your normal cycle if you run them. Most smaller shops don't use either and can ignore this one.
Sources (1)
What this means for you — Security leader:Update IBM MQ to 9.1.0.37 LTS, 9.2.0.43 LTS or later and Langflow OSS to 1.11.6 or later on your normal patch cycle.
What this means for you — Lean IT orgs:If you run IBM MQ or Langflow yourself, apply the fixes released in this advisory; most lean teams don't use these products and can ignore it.
What this means for you — MSP:Check client estates for IBM MQ versions prior to 9.1.0.37/9.2.0.43 LTS or Langflow OSS ≤1.11.5 and schedule the IBM-provided updates.
What this means for you — Researcher:IBM advisory AV26-922 discloses vulnerabilities in Langflow OSS (≤1.11.5) and multiple IBM MQ releases; see CCCS link for details.