Junglewise Threat Intelligence

CVE-2026-9319: IBM WebSphere Application Server remote code execution in JAX-WS

CVE-2026-9319 · Severity: critical · CVSS 9 · Published 2026-06-01

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to a critical security flaw. An attacker could exploit this vulnerability to take full control of the server and execute unauthorized commands. This could lead to a total compromise of the application, including the theft of sensitive customer data or a complete shutdown of business operations.

Technical details

IBM WebSphere Application Server (versions 8.5 and 9.0) contains a deserialization of untrusted data vulnerability (CWE-502) within JAX-WS endpoints when WS-Security is enabled. The flaw allows a remote, unauthenticated attacker to send specially crafted input that, when processed, executes arbitrary code on the host system. While the attack vector is network-based and requires no user interaction, the complexity is rated as high, likely due to specific configuration requirements or the need for precise payload construction. IBM has released interim fixes (APAR PH71454) and plans to include permanent fixes in Fix Packs 9.0.5.29 and 8.5.5.30.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-01: patched: Interim fixes released; fix packs scheduled for Q3 2026

References

Related threats