Unauthenticated RAG Poisoning in IBM Financial Transaction Manager Exposes MCP Tool Calls to Hijacking
IBM released a security bulletin on September 23, 2026, addressing 47 vulnerabilities in its Financial Transaction Manager (FTM) for RedHat OpenShift, including CVE-2026-18875 with a CVSS score of 7.3. This flaw allows unauthenticated attackers to poison the AI agent's vector database, potentially leading to unauthorized financial actions. The vulnerability affects FTM versions 4.0.6.0 through 4.0.10.0, and IBM recommends upgrading to version 4.0.11.0 to mitigate risks.
How this was made

The 30-second read
Why it matters
The disclosed RAG poisoning vulnerability could allow attackers to manipulate AI decision contexts, leading to unauthorized payments.
Market read
Investors may reassess exposure to IBM's enterprise software segment pending remediation.
What to watch
Potential for increased demand for third‑party security solutions and consulting services.
Background
IBM's Financial Transaction Manager is used for automated transaction processing on RedHat OpenShift; the bulletin lists 47 vulnerabilities.
Ticker impact
IBM disclosed a new security bulletin (CVE-2026-18875) affecting its Financial Transaction Manager, requiring immediate patching.
Short-term downside pressure until patches are applied; limited long-term impact.
First disclosure of a medium‑severity vulnerability in a core financial product creates immediate risk perception.
Market effects
Highlights security risks in AI‑driven financial software, may prompt broader scrutiny of similar platforms.
Primarily affects enterprises using IBM FTM on RedHat OpenShift, with limited regional spillover.
Raises awareness of supply‑chain security in AI financial services globally.
Counterpoint
If IBM quickly releases patches, the issue may be contained with minimal market impact.
Key entities
- CompanyIBM
Issuer of the vulnerable Financial Transaction Manager.
- VulnerabilityCVE-2026-18875
RAG poisoning flaw with CVSS 7.3.




