CVE-2026-3144: IBM API Connect

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

Affected products

  • IBM API Connect: from 12.1.0.0, before 12.1.1.0 (fixed in 12.1.1.0)

Published 2026-07-08. Last modified 2026-07-10.