CVE-2026-14979: IBM Engineering Lifecycle Management

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.

Affected products

  • IBM Engineering Lifecycle Management: version 7.0.3 only; version 7.1.0 only; version 7.2.0 only

Published 2026-07-17. Last modified 2026-08-11.