Threat · curated 29 Sep 2026
IBM FTM RAG Poisoning CVE-2026-18875 | Redbot Labs
First reported redbotsecurity.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-18875 shows how unauthenticated RAG poisoning of a payment agent's vector store can escalate into unauthorized financial transactions and data exfiltration via MCP-connected tools, a concrete indirect-prompt-injection risk for agentic deployments.
IBM disclosed CVE-2026-18875, a vulnerability in the Financial Transaction Manager AI agent that lets unauthenticated attackers insert malicious runbook content into the agent's vector database. The poisoned retrieval content could steer subsequent MCP tool calls toward unauthorized payment operations or payment-data exfiltration. IBM rates the flaw 7.3 and identifies FTM for Red Hat OpenShift version 4.0.11.0 as the fix.