CVE-2026-17617: IBM Application Gateway Operator

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

Affected products

  • IBM Application Gateway Operator: from 22.2.0, up to and including 26.6.0

Published 2026-08-05. Last modified 2026-08-10.