OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-18872

CRITICAL · CVSS 9.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Financial Transaction Manager for RedHat OpenShift is susceptible to stored cross-site scripting in its NetworkAcknowledgement component, allowing attackers to inject malicious scripts into stored data. This vulnerability can lead to session hijacking and unauthorized payment actions by executing scripts in the browsers of authenticated operators. Organizations using this software should prioritize remediation to protect against potential exploitation and financial fraud.

CVE
CVE-2026-18872
Severity
CRITICAL
CVSS
9.3
EPSS
0.19%

Original NVD Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.