The Point: IBM Semeru Runtime contains a critical vulnerability that enables remote code execution without authentication.
A security flaw in IBM Semeru Runtime allows attackers to execute arbitrary code remotely. The vulnerability affects multiple products, including the Power Hardware Management Console and IBM DB2.
IBM Semeru Runtime is a Java runtime environment used in various IBM products. A vulnerability in this component allows unauthenticated remote attackers to execute code on affected systems.
Multiple systems using Semeru are affected, particularly the Power Hardware Management Console and IBM DB2. Exact versions and technical details can be found in the official IBM security notice and the CERT-Bund advisory.
CISOs should immediately check which Semeru versions are in use in their environment and apply available security updates. Since the vulnerability is remotely exploitable and requires no authentication, it poses a high risk and should be treated with high priority.
Source: wid.cert-bund.de · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.