CRITICAL 9.3 CVE-2026-18872 Published 23 Sept 2026

IBM Financial Transaction Manager UI Stored XSS Vulnerability

Worried this affects your website?

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42).

A malicious actor can inject script into stored network acknowledgement data. The script executes in authenticated operator browsers.

  • Session hijacking
  • Unauthorized operator-level payment transactions

Reference: CVE-2026-18872 on NVD

← Back to Security News