VendorsIBMcontextforgeall versions
Vulnerabilities

IBM Contextforge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-78573
IBM ContextForge MCP Gateway is affected by use of default credentials
Published 2026-09-10 · Analyzed
9.8EPSS 0.006
CVE-2026-77822
IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint
Published 2026-09-04 · Analyzed
9.6EPSS 0.004
CVE-2026-18486
IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution
Published 2026-09-04 · Analyzed
8.8EPSS 0.003
CVE-2026-18905
IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation
Published 2026-09-04 · Analyzed
7.7EPSS 0.003
CVE-2026-18489
IBM ContextForge Translate is affected by cross-client credential context confusion
Published 2026-09-04 · Analyzed
7.4EPSS 0.003