started · updated
Cybersecurity alerts issued for Windows, IBM, and vm2 software
Multiple critical cybersecurity vulnerabilities have been identified across various software platforms. The CERT-Bund reported several flaws in the vm2 JavaScript sandbox package, which could allow attackers to perform denial-of-service attacks, execute arbitrary code, disclose information, or manipulate data.
In the Windows ecosystem, CISA has added a critical Internet Key Exchange (IKE) vulnerability (CVE-2026-33824) to its Known Exploited Vulnerabilities catalog. This double-free vulnerability carries a CVSS score of 9.8 and can be exploited remotely without credentials. Notably, Microsoft’s advisory currently disputes the active exploitation status, creating a discrepancy between federal reporting and vendor assessment.
IBM has also disclosed two critical vulnerabilities. CVE-2026-14525 affects WebSphere Application Server Liberty, potentially allowing authentication bypass when specific rtcomm components are active. Additionally, CVE-2026-17181 affects Db2 Mirror for i, presenting a path-traversal risk that could enable remote attackers to write files to arbitrary locations on a system.