• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ibm warns of critical api connect bug allowing remote authentication

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

You are here: Home / General Cyber Security News / IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass
December 31, 2025

IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application.

The vulnerability, tracked as CVE-2025-13915, is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an authentication bypass flaw.

“IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application,” the tech giant said in a bulletin.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The shortcoming affects the following versions of IBM API Connect –

  • 10.0.8.0 through 10.0.8.5
  • 10.0.11.0

Cybersecurity

Customers are advised to follow the steps outlined below –

  • Download the fix from Fix Central
  • Extract the files: Readme.md and ibm-apiconnect-<version>-ifix.13195.tar.gz
  • Apply the fix based on the appropriate API Connect version

“Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exposure to this vulnerability,” the company added.

API Connect is an end-to-end application programming interface (API) solution that allows organizations to create, test, manage, and secure APIs located on cloud and on-premises. It’s used by companies like Axis Bank, Bankart, Etihad Airways, Finologee, IBS Bulgaria, State Bank of India, Tata Consultancy Services, and TINE.

While there is no evidence of the vulnerability being exploited in the wild, users are advised to apply the fixes as soon as possible for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «u.s. treasury lifts sanctions on three individuals linked to intellexa U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass
  • U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
  • CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
  • Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware
  • How to Integrate AI into Modern SOC Workflows
  • Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
  • ⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More
  • 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
  • MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
  • Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

Copyright © TheCyberSecurity.News, All Rights Reserved.