Executive brief
IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is affected by a critical security flaw. An unauthenticated attacker can exploit this vulnerability over the network to bypass security controls or take full control of the server. This could lead to the theft of sensitive data, disruption of business operations, or unauthorized access to internal corporate systems.
Technical details
A critical unsafe deserialization vulnerability (CWE-502) exists in IBM WebSphere Application Server traditional versions 8.5 and 9.0. The flaw allows for the processing of untrusted data before authentication has occurred. A remote, unauthenticated attacker can exploit this by sending specially crafted serialized objects over the network. Successful exploitation can lead to a complete authentication bypass or remote code execution (RCE) with the privileges of the application server process. IBM has released interim fix PH72166 and plans to include the fix in upcoming Fix Packs 9.0.5.29 and 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.30
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Interim fix PH72166 released