CVE-2025-13915: IBM API Connect

Critical severity, CVSS 9.8. EPSS: 9% chance of exploitation in the next 30 days.

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

Affected products

  • IBM API Connect: from 10.0.8.0, up to and including 10.0.8.5; version 10.0.11.0 only

Published 2025-12-26. Last modified 2026-10-07.