CVE-2026-3207: TIBCO Bpm Enterprise
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Affected products
- TIBCO Bpm Enterprise: from 4.3.0, before 4.3.5 (fixed in 4.3.5)
Published 2026-03-17. Last modified 2026-06-17.