Junglewise Threat Intelligence

CVE-2026-9311: IBM WebSphere Application Server remote code execution via security bypass

CVE-2026-9311 · Severity: critical · CVSS 9 · Published 2026-06-01

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to a security flaw that allows remote attackers to execute unauthorized code. If exploited, an attacker could take full control of the server, potentially leading to data theft, service disruption, or further access into the corporate network. Organizations are advised to apply the available security patches immediately to protect their environments.

Technical details

IBM WebSphere Application Server versions 8.5 and 9.0 are vulnerable to remote code execution (RCE) due to a bypass of security controls. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code), indicating a code injection flaw. An attacker can exploit this over the network without authentication, though the CVSS vector suggests high attack complexity. Successful exploitation allows for complete compromise of the confidentiality, integrity, and availability of the host system. IBM has released interim fix PH71453 to address this issue, with permanent fixes planned for fix packs 9.0.5.29 and 8.5.5.30.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-01: patched: Interim fix PH71453 released

References

Related threats