Back

CRITICAL

Multiple Vulnerabilities in IBM Concert Software

Published Sep 23, 2026

Description

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1

Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 23, 2026
Updated Sep 25, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Sep 23, 2026
Updated Sep 25, 2026
Exploited since n/a
EUVD-2026-85669