By Heath Callahan
Publication Date: 2026-09-25 01:47:00
Analysis
A severe flaw in IBM’s FTM AI agent server lets unauthenticated attackers inject malicious runbooks into vector stores, weaponizing the text retrieved by autonomous payment workflows.
On September 23, 2026, IBM released Security Bulletin node/7288641, which addresses a total of 47 vulnerabilities identified within the IBM Financial Transaction Manager (FTM) for RedHat OpenShift platform. Among these disclosures, CVE-2026-18875 stands out as a significant security concern, carrying a CVSS score of 7.3. This vulnerability highlights the increasing complexity of securing AI-integrated financial infrastructure, specifically regarding the integrity of Retrieval-Augmented Generation (RAG) pipelines used in automated transaction processing.
The technical root of CVE-2026-18875 is located within the FTM AI agent server, specifically at api.vectordb.runbooks.js:51. The vulnerability manifests as a RAG poisoning flaw that allows an unauthenticated attacker to execute a network-based…

