IBM
IBM Websphere Application Server: vulnerabilities and CVEs
IBM Websphere Application Server has 519 published vulnerabilities, 83 of them in the last 12 months. 35 are rated critical and 1 are listed by CISA as actively exploited.
CVEs519
Last 12 months83
Critical35
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-7450 | Critical (9.8) | 98% | ⚠ Active exploitation | Jan 2, 2016 | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11722 | Medium (4.8) | 0.18% | — | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. |
| CVE-2026-11711 | Medium (6.5) | 0.38% | — | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. |
| CVE-2026-11710 | Medium (6.5) | 0.23% | — | Sep 18, 2026 | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. |
| CVE-2026-11549 | Medium (6.5) | 0.23% | — | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability. |
| CVE-2026-11548 | Medium (4.8) | 0.18% | — | Sep 18, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. |
| CVE-2026-11545 | Low (3.7) | 0.26% | — | Sep 18, 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. |
| CVE-2026-11540 | Medium (5.3) | 0.30% | — | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. |
| CVE-2026-11539 | Medium (5.3) | 0.30% | — | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector. |
| CVE-2026-11538 | Medium (5.3) | 0.16% | — | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies. |
| CVE-2026-11537 | Medium (4.3) | 0.18% | — | Sep 18, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. |
| CVE-2026-10841 | Medium (4.8) | 0.18% | — | Sep 18, 2026 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. |
| CVE-2026-16435 | Medium (5.9) | 0.31% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. |
| CVE-2026-16190 | Low (3.1) | 0.16% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. |
| CVE-2026-16189 | Medium (4.8) | 0.22% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. |
| CVE-2026-16188 | Medium (5.3) | 0.27% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. |
| CVE-2026-16187 | Medium (6.5) | 0.25% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. |
| CVE-2026-16186 | Medium (5.4) | 0.18% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. |
| CVE-2026-16185 | Medium (6.4) | 0.20% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet. |
| CVE-2026-15887 | Medium (5.4) | 0.18% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests. |
| CVE-2026-15634 | Medium (6.5) | 0.25% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending… |
| CVE-2026-15412 | Medium (6.5) | 0.23% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a… |
| CVE-2026-15396 | Medium (6.5) | 0.25% | — | Sep 14, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending… |
| CVE-2026-9667 | Medium (5.3) | 0.43% | — | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. |
| CVE-2026-9327 | High (8.1) | 0.37% | — | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. |
| CVE-2026-9176 | High (7.1) | 0.16% | — | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized… |
| CVE-2026-9338 | Medium (5.3) | 0.49% | — | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource… |
| CVE-2026-9336 | High (7.5) | 0.77% | — | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to… |
| CVE-2026-14525 | Critical (9.4) | 0.55% | — | Aug 13, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. |
| CVE-2026-10571 | Medium (5.3) | 0.59% | — | Aug 13, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to… |
| CVE-2026-18499 | High (8.1) | 0.42% | — | Aug 12, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by IBM
AIX · 551DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142Rational Engineering Lifecycle Manager · 141