IBM WebSphere Application Server
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM WebSphere Application Server.
By the Year
In 2026 there have been 35 vulnerabilities in IBM WebSphere Application Server with an average score of 7.6 out of ten. Last year, in 2025 WebSphere Application Server had 11 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.22.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 35 | 7.63 |
| 2025 | 11 | 6.41 |
| 2024 | 19 | 6.43 |
| 2023 | 8 | 6.39 |
| 2022 | 11 | 6.41 |
| 2021 | 8 | 5.90 |
| 2020 | 22 | 7.26 |
| 2019 | 18 | 5.92 |
| 2018 | 24 | 0.00 |
It may take a day or so for new WebSphere Application Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM WebSphere Application Server Security Vulnerabilities
IBM WAS 9.0/8.5 RCE via SOAP/JMX Connector
CVE-2026-11536
8.5 - High
- July 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Marshaling, Unmarshaling
IBM WAS DoS via Crafted HTTP Request in 8.5-9.0 and Liberty 17-26
CVE-2026-9322
7.5 - High
- July 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
Resource Exhaustion
IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7 Bypass Security Constraints
CVE-2026-10842
7.5 - High
- July 30, 2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
Authentication Bypass by Alternate Name
IBM WSS/LIBERTY SIP SSRF via sipServlet-1.1 pre-26.0.0.9
CVE-2026-14529
9.4 - Critical
- July 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Missing Authentication for Critical Function
Broken Access Control in IBM WebSphere App Server 8.5/9.0 Admin Console
CVE-2026-14446
9.8 - Critical
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Missing Authentication for Critical Function
IBM WAS 8.5/9.0 Traditional XSS Vulnerability
CVE-2026-14515
6.1 - Medium
- July 28, 2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.
XSS
IBM WebSphere App Server 9.0/8.5 pre-auth unsafe deserialization
CVE-2026-14512
9.8 - Critical
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
Marshaling, Unmarshaling
IBM WebSphere AppServer 8.5/9.0 Remote Info Disclosure
CVE-2026-14528
7.4 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Insertion of Sensitive Information into Log File
IBM WebSphere AppServer 8.5/9.0 RCE via Unsafe Deserialization
CVE-2026-14974
8.1 - High
- July 28, 2026
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
Marshaling, Unmarshaling
IBM WebSphere WAS & Liberty DoS via HTTP Channel Unbounded Resource Allocation
CVE-2026-14981
7.5 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Resource Exhaustion
IBM WS HTTP Resp Smuggling via HTTP version token (pre 9.0/8.5, Liberty 17+)
CVE-2026-15064
8.7 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
HTTP Request Smuggling
IBM WAS HTTP Request Smuggling via TRACE (8.5/9.0; Liberty 17-26)
CVE-2026-15325
8.7 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
HTTP Request Smuggling
Request smuggling in IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7
CVE-2026-15328
7.4 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
HTTP Request Smuggling
IBM WAS 9.0/8.5 Auth Bypass via Unauthenticated Request
CVE-2026-16184
7 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
AuthZ
HTTP Req Smuggling in IBM WebSphere WSAS 8.5/9.0 & Liberty 17.0.0.3-26.0.0.6
CVE-2026-11541
7.4 - High
- June 30, 2026
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
HTTP Request Smuggling
IBM WAS 9.0/8.5 XSS in Admin Console
CVE-2026-11594
8.5 - High
- June 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
XSS
IBM WebSphere App Server 8.5-9.0 Sensitive Info Disclosure via Admin Console Help
CVE-2026-11595
4.3 - Medium
- June 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
Directory traversal
XSS on IBM WAS 9.0/8.5 Admin Console Help System
CVE-2026-11708
9.3 - Critical
- June 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
XSS
IBM WebSphere App Server 8.5-9.0: XSS in Admin Help System
CVE-2026-11712
9.3 - Critical
- June 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
XSS
Denial of Service via WebSphere WebServer Plug-in in IBM WAS 7.3-7.6
CVE-2026-10852
5.9 - Medium
- June 22, 2026
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
NULL Pointer Dereference
IBM WebSphere App Server DoS: crafted request (pre 9.0/8.5, Liberty 1726)
CVE-2026-9320
5.9 - Medium
- June 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
WAS DoS via crafted request (8.59.0 & Liberty 17.026.0)
CVE-2026-9071
7.5 - High
- June 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
IBM WAS 9.0/8.5 SSRF via Ajax Proxy
CVE-2026-9006
7.4 - High
- June 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
SSRF
IBM WebSphere App Server 9.0/8.5/Liberty 17-26 HTTP Request Smuggling
CVE-2026-8646
7.4 - High
- June 22, 2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
HTTP Request Smuggling
IBM WAS 8.5/9.0 JAX-WS Auth Bypass Remote Exploit
CVE-2026-10845
7.3 - High
- June 22, 2026
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
authentification
Remote Code Exec in IBM WebSphere WebServer Plugin (IBM i 7.37.6)
CVE-2026-9072
8.1 - High
- June 22, 2026
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
Code Injection
IBM WebSphere Web Server Plug-in RCE (7.3-7.6)
CVE-2026-8858
7.5 - High
- June 22, 2026
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
Code Injection
IBM WAS 9.0/8.5 SAML WebSSO RCE via Deserialization Gadget
CVE-2026-9330
8.5 - High
- June 01, 2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
Marshaling, Unmarshaling
IBM WAS 8.5-9.0 RCE via Deserialization in JAX-WS WS-Security
CVE-2026-9319
9 - Critical
- June 01, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
Marshaling, Unmarshaling
IBM WebSphere App Server 8.5-9.0 RCE via Security Control Bypass
CVE-2026-9311
9 - Critical
- June 01, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
Code Injection
IBM WebSphere App Server 8.5/9.0 Identity Spoofing Vulnerability
CVE-2026-8644
9.1 - Critical
- June 01, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Authentication Bypass by Spoofing
IBM WebSphere App Server Liberty DoS via crafted request (v19.0-26.0)
CVE-2026-4410
4.8 - Medium
- May 27, 2026
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
SSRF in IBM WebSphere Application Server Liberty 17.0.0.3-26.0.0.3
CVE-2026-1561
5.4 - Medium
- March 25, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
SSRF
IBM WebSphere Application Server 9.0/8.5 Weak Security Admin (CVE-2025-13333)
CVE-2025-13333
4.4 - Medium
- February 17, 2026
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
Improperly Implemented Security Check for Standard
IBM WAS Liberty 17.0.0.3-26.0.0.1 ZIP Path Traversal Arbitrary Code Execution
CVE-2025-14914
7.6 - High
- February 02, 2026
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
Directory traversal
IBM WebSphere App Server 8.5/9.0 & Lib 17.0.0.3-25.0.0.12 XSS URL Redirect
CVE-2025-12635
5.4 - Medium
- December 08, 2025
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of user-supplied input. An attacker could exploit this vulnerability by using a specially crafted URL to redirect the user to a malicious site.
XSS
IBM WebSphere AS 8.5/9.0 DoS via Memory Exhaustion
CVE-2025-36099
4.9 - Medium
- September 29, 2025
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit this vulnerability to cause the server to consume memory resources.
Allocation of Resources Without Limits or Throttling
IBM WAS Liberty 18.0.0.2–25.0.0.8 DOS via memory exhaustion
CVE-2025-36047
5.3 - Medium
- August 14, 2025
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Allocation of Resources Without Limits or Throttling
IBM WebSphere AS 8.5/9.0 TLS Weak Cipher Suite
CVE-2025-33142
7.5 - High
- August 14, 2025
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
Improper Certificate Validation
IBM WebSphere Liberty 17.0.0.3-25.0.0.8 Stored XSS via Web UI
CVE-2025-36000
4.8 - Medium
- August 12, 2025
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM WebSphere Liberty JMS Config Ignorance 17.0.0.3-25.0.0.8
CVE-2025-36124
7.5 - High
- August 12, 2025
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration
Privilege Chaining
IBM WebSphere App Server Config Bypass (9.0, 17.0.0.3-25.0.0.7)
CVE-2024-56339
7.5 - High
- August 07, 2025
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
IBM WebSphere App Server DoS via Stack Overflow (before 25.0.0.7)
CVE-2025-36097
7.5 - High
- July 16, 2025
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to consume excessive memory resources.
Stack Overflow
RCE via Serialized Objects in IBM WebSphere App Server 8.5 & 9.0
CVE-2025-36038
9.8 - Critical
- June 25, 2025
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
Marshaling, Unmarshaling
IBM WebSphere Application Server 8.5/9.0 XSS in Web UI
CVE-2025-33104
7.6 - High
- May 14, 2025
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
SSRF Vulnerability in IBM WebSphere App Server 8.5/9.0
CVE-2025-27907
2.7 - Low
- April 22, 2025
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
SSRF
IBM WebSphere Application Server 8.5/9.0 XSS Vulnerability in Web UI
CVE-2024-45087
4.8 - Medium
- November 11, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM WebSphere XXE Injection Vulnerability
CVE-2024-45086
5.5 - Medium
- November 04, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
XXE
IBM WebSphere App Server 8.5/9.0 XSS via Web UI (CVE-2024-45071)
CVE-2024-45071
4.8 - Medium
- October 16, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM WebSphere App Server 8.5/9.0 XXE Vulnerable XML Parser
CVE-2024-45072
5.5 - Medium
- October 16, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
XXE
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM WebSphere Application Server or by IBM? Click the Watch button to subscribe.