Vulnerabilities & PatchesEmerging1 src
Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems
IBM has released security fixes for Financial Transaction Manager for Red Hat OpenShift after identifying multiple vulnerabilities that could enable remote code execution, unauthorized payment actions, credential theft, data exposure, and service disruption. The most severe flaws carry CVSS scores of up to 9. 9 and affect FTM versions 4. 0. 6. 0 through 4. 0. 10. 0.
Financial Transaction Manager is used to manage and process payment workflows. Because the platform can handle payment data, transaction rules, operator sessions, and business logic, successful exploitation could have serious consequences for financial organizations.
The most critical issue is CVE-2026-18163, a remote code execution flaw caused by unsafe deserialization of untrusted data. It has a CVSS score of 9. 8 and can be exploited remotely without authentication or user interaction.