Technology · IBM
IBM WebSphere Application Server vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 54 vulnerabilities in IBM WebSphere Application Server: 0 in the last 7 days and 39 in the last 90 days, 10 of them critical and 1 exploited in the wild. The most recent, CVE-2026-10841, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 39
- Critical, all time
- 10
- Exploited in the wild
- 1
About IBM WebSphere Application Server
A Java Enterprise Edition application server used for hosting and managing enterprise web applications.
Latest IBM WebSphere Application Server vulnerabilities
- CVE-2026-10841: IBM WebSphere Application Server HTTP request smugglingmediumCVSS 4.2EPSS 0.2%
- CVE-2026-16435: IBM WebSphere Application Server authentication bypass in XD/Intelligent-ManagementmediumCVSS 5.9EPSS 0.3%
- CVE-2026-16190: IBM WebSphere Application Server authorization bypasslowCVSS 3.1EPSS 0.2%
- CVE-2026-16189: IBM WebSphere Application Server log injectionmediumCVSS 4.8EPSS 0.2%
- CVE-2026-16188: IBM WebSphere Application Server log injection vulnerabilitymediumCVSS 5.3EPSS 0.3%
- CVE-2026-16187: IBM WebSphere Application Server authentication bypass in admin consolemediumCVSS 6.5EPSS 0.3%
- CVE-2026-16186: IBM WebSphere Application Server reflected cross-site scriptingmediumCVSS 5.4EPSS 0.2%
- CVE-2026-16185: IBM WebSphere Application Server authentication bypass in admin console servletmediumCVSS 6.4EPSS 0.2%
- CVE-2026-15887: IBM WebSphere Application Server blind server-side request forgery in SOAPmediumCVSS 5.4EPSS 0.2%
- CVE-2026-15634: IBM WebSphere Application Server HTTP request smuggling via transfer-encoding headermediumCVSS 6.5EPSS 0.3%
- CVE-2026-15412: IBM WebSphere Application Server open redirect phishing attackmediumCVSS 6.5EPSS 0.2%
- CVE-2026-15396: IBM WebSphere Application Server HTTP request smuggling via transfer-encodingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-9667: IBM WebSphere Application Server server-side request forgerymediumCVSS 5.3EPSS 0.4%
- CVE-2026-9327: IBM WebSphere Application Server privilege escalation in security configurationmediumCVSS 6.3EPSS 0.4%
- CVE-2026-9176: IBM WebSphere Application Server authentication bypassmediumCVSS 6.7EPSS 0.2%
- CVE-2026-9338: IBM WebSphere Application Server denial of service via crafted requestmediumCVSS 5.3EPSS 0.5%
- CVE-2026-9336: IBM WebSphere Application Server denial of service via HTTP requestmediumCVSS 6.5EPSS 0.8%
- CVE-2026-18499: IBM WebSphere Application Server Liberty privilege escalation in collectiveshighCVSS 8.1EPSS 0.4%
- CVE-2026-8400: IBM WebSphere Application Server arbitrary class instantiation via IIOPhighCVSS 8.1EPSS 0.5%
- CVE-2026-11536: IBM WebSphere Application Server remote code execution in SOAP/JMX connectorhighCVSS 8.5
- CVE-2026-9322: IBM WebSphere Application Server denial of service via crafted HTTP requesthighCVSS 7.5
- CVE-2026-10842: IBM WebSphere Application Server security bypass in appSecurity featurehighCVSS 7.5
- CVE-2026-11707: IBM WebSphere Application Server XSS in administrative console login pagecriticalCVSS 9.3
- CVE-2026-11383: IBM WebSphere Application Server XSS in Administrative ConsolemediumCVSS 5.4
- CVE-2026-14529: IBM WebSphere Application Server SSRF in SIP containercriticalCVSS 9.4
Most severe IBM WebSphere Application Server vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2015-7450: IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.criticalexploited in the wildCVSS 9.8
- CVE-2026-14512: IBM WebSphere Application Server unsafe deserializationcriticalCVSS 9.8
- CVE-2026-14446: IBM WebSphere Application Server privilege escalation in administrative consolecriticalCVSS 9.8
- CVE-2026-14529: IBM WebSphere Application Server SSRF in SIP containercriticalCVSS 9.4
- CVE-2026-11707: IBM WebSphere Application Server XSS in administrative console login pagecriticalCVSS 9.3
- CVE-2026-11712: IBM WebSphere Application Server XSS in administrative console help systemcriticalCVSS 9.3
- CVE-2026-11708: IBM WebSphere Application Server XSS in administrative console help systemcriticalCVSS 9.3
- CVE-2026-8644: IBM WebSphere Application Server identity spoofing authentication bypasscriticalCVSS 9.1
- CVE-2026-9319: IBM WebSphere Application Server remote code execution in JAX-WScriticalCVSS 9
- CVE-2026-9311: IBM WebSphere Application Server remote code execution via security bypasscriticalCVSS 9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 5 | 2 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 15 | 4 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 5 | 0 | |
| 14 Sep 2026 | 12 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/websphere-application-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM WebSphere Application Server vulnerabilities", https://junglewise.ai/threats/technologies/websphere-application-server, 26 September 2026.