CRITICAL: IBM DataPower Gateway 10.5.0.0 – 10.6.6 & 11.0.0.0 – 11.0.0.2 impacted by CVE-2026-16340. Remote code execution risk via out-of-bounds write. Assess & patch when available. radar.offseq.com/threat/cve-2026-16…...
radar.offseq.com
CVE-2026-16340: CWE-787 Out-of-bounds Write in IBM DataPower Gateway 10.6CD
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word