IBM DataPower Gateway fails to reject empty passwords during LDAP authentication, letting a remote attacker obtain administrative access to the gateway enforcing policy for everything behind it.
Read more about Emerging Threat: (CVE-2026-107406) NetScaler ADC and Gateway Remote Code Execution via SAML