Threat · curated 29 Sep 2026

IBM FTM RAG Poisoning CVE-2026-18875 | Redbot Labs

Coverage timeline

29 Sep 2026redbotsecurity.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-18875 shows how unauthenticated RAG poisoning of a payment agent's vector store can escalate into unauthorized financial transactions and data exfiltration via MCP-connected tools, a concrete indirect-prompt-injection risk for agentic deployments.

IBM disclosed CVE-2026-18875, a vulnerability in the Financial Transaction Manager AI agent that lets unauthenticated attackers insert malicious runbook content into the agent's vector database. The poisoned retrieval content could steer subsequent MCP tool calls toward unauthorized payment operations or payment-data exfiltration. IBM rates the flaw 7.3 and identifies FTM for Red Hat OpenShift version 4.0.11.0 as the fix.