Critical IBM API Connect Flaw CVE-2025-13915 Alert
ID: c3770491-dec3-5761-a077-a3c06a02132f
STIX ID: report--c3770491-dec3-5761-a077-a3c06a02132f
Feed Name: Cyble Blog
Threat Score
The Cyber Security Agency of Singapore and IBM have warned of a critical authentication-bypass vulnerability (CVE-2025-13915, CVSS 9.8) in IBM API Connect (versions 10.0.8.0–10.0.8.5 and 10.0.11.0). IBM released interim fixes and recommends immediate upgrading; temporary mitigation includes disabling Developer Portal self-service sign-up. No active exploitation has been observed, and EPSS is 0.37, but the remote, no-interaction nature and high impact make patching urgent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
