« Back to list

IBM

IBM Websphere Application Server: vulnerabilities and CVEs

IBM Websphere Application Server has 519 published vulnerabilities, 83 of them in the last 12 months. 35 are rated critical and 1 are listed by CISA as actively exploited.

CVEs519
Last 12 months83
Critical35
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2015-7450Critical (9.8)98%⚠ Active exploitationJan 2, 2016
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-11722Medium (4.8)0.18%—Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-11711Medium (6.5)0.38%—Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
CVE-2026-11710Medium (6.5)0.23%—Sep 18, 2026
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
CVE-2026-11549Medium (6.5)0.23%—Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.
CVE-2026-11548Medium (4.8)0.18%—Sep 18, 2026
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-11545Low (3.7)0.26%—Sep 18, 2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.
CVE-2026-11540Medium (5.3)0.30%—Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
CVE-2026-11539Medium (5.3)0.30%—Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
CVE-2026-11538Medium (5.3)0.16%—Sep 18, 2026
IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
CVE-2026-11537Medium (4.3)0.18%—Sep 18, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.
CVE-2026-10841Medium (4.8)0.18%—Sep 18, 2026
IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
CVE-2026-16435Medium (5.9)0.31%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
CVE-2026-16190Low (3.1)0.16%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.
CVE-2026-16189Medium (4.8)0.22%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
CVE-2026-16188Medium (5.3)0.27%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
CVE-2026-16187Medium (6.5)0.25%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
CVE-2026-16186Medium (5.4)0.18%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
CVE-2026-16185Medium (6.4)0.20%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
CVE-2026-15887Medium (5.4)0.18%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requests.
CVE-2026-15634Medium (6.5)0.25%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending…
CVE-2026-15412Medium (6.5)0.23%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a…
CVE-2026-15396Medium (6.5)0.25%—Sep 14, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending…
CVE-2026-9667Medium (5.3)0.43%—Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
CVE-2026-9327High (8.1)0.37%—Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
CVE-2026-9176High (7.1)0.16%—Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized…
CVE-2026-9338Medium (5.3)0.49%—Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource…
CVE-2026-9336High (7.5)0.77%—Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to…
CVE-2026-14525Critical (9.4)0.55%—Aug 13, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
CVE-2026-10571Medium (5.3)0.59%—Aug 13, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to…
CVE-2026-18499High (8.1)0.42%—Aug 12, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application53
  2. T1059 Command and Scripting Interpreter13
  3. T1078 Valid Accounts10
  4. T1499.004 Application or System Exploitation9
  5. T1005 Data from Local System7
  6. T1210 Exploitation of Remote Services7

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by IBM