IBM's Financial Transaction Manager Hit with Critical RAG Poisoning Flaw
A critical vulnerability has been discovered in IBM's Financial Transaction Manager (FTM) for RedHat OpenShift platform. The flaw, known as CVE-2026-18875, allows unauthenticated attackers to inject malicious content into the FTM AI agent server's vector database.
The vulnerability is caused by a RAG poisoning flaw that affects the retrieval of information from the compromised database. This can lead to unauthorized payment actions and the exfiltration of sensitive financial data.
IBM released a security bulletin on September 23, 2026, addressing a total of 47 vulnerabilities in the FTM. CVE-2026-18875 has a CVSS score of 7.3 and is considered a significant security concern.
The vulnerability impacts FTM versions 4.0.6.0 through 4.0.10.0, including the iFix6 Refresh. To mitigate the risks, operators must upgrade their FTM for RedHat OpenShift environments to version 4.0.11.0.