CVE-2026-17617: IBM Application Gateway Operator
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
Affected products
- IBM Application Gateway Operator: from 22.2.0, up to and including 26.6.0
Published 2026-08-05. Last modified 2026-08-10.