Technology · IBM
IBM WebSphere Application Server Liberty vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in IBM WebSphere Application Server Liberty: 0 in the last 7 days and 24 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-10841, was published on 18 September 2026.
- Last 7 days
- 0
- Last 90 days
- 24
- Critical, all time
- 1
- Exploited in the wild
- 0
About IBM WebSphere Application Server Liberty
A lightweight Java application server designed for cloud-native development and microservices.
Latest IBM WebSphere Application Server Liberty vulnerabilities
- CVE-2026-10841: IBM WebSphere Application Server HTTP request smugglingmediumCVSS 4.2EPSS 0.2%
- CVE-2026-15634: IBM WebSphere Application Server HTTP request smuggling via transfer-encoding headermediumCVSS 6.5EPSS 0.3%
- CVE-2026-15412: IBM WebSphere Application Server open redirect phishing attackmediumCVSS 6.5EPSS 0.2%
- CVE-2026-15396: IBM WebSphere Application Server HTTP request smuggling via transfer-encodingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-18499: IBM WebSphere Application Server Liberty privilege escalation in collectiveshighCVSS 8.1EPSS 0.4%
- CVE-2026-8400: IBM WebSphere Application Server arbitrary class instantiation via IIOPhighCVSS 8.1EPSS 0.5%
- CVE-2026-9322: IBM WebSphere Application Server denial of service via crafted HTTP requesthighCVSS 7.5
- CVE-2026-10842: IBM WebSphere Application Server security bypass in appSecurity featurehighCVSS 7.5
- CVE-2026-14980: IBM WebSphere Application Server Liberty CSRF in collectiveControllerhighCVSS 8.3
- CVE-2026-11897: IBM WebSphere Application Server Liberty denial of service in HTTP/2highCVSS 7.5
- CVE-2026-2482: IBM WebSphere Application Server Liberty CSRF in collectiveControllerlowCVSS 3.1
- CVE-2026-14529: IBM WebSphere Application Server SSRF in SIP containercriticalCVSS 9.4
- CVE-2026-15328: IBM WebSphere Application Server HTTP request smugglinghighCVSS 7.4
- CVE-2026-15325: IBM WebSphere Application Server HTTP request smuggling in TRACE requestshighCVSS 8.7
- CVE-2026-15280: IBM WebSphere Application Server Liberty path traversal in Collective ControllerhighCVSS 7.5
- CVE-2026-15064: IBM WebSphere Application Server HTTP response smugglinghighCVSS 8.7
- CVE-2026-15057: IBM WebSphere Application Server Liberty denial of service via uncontrolled heap allocationhighCVSS 7.5
- CVE-2026-14981: IBM WebSphere Application Server denial of service in HTTP channelhighCVSS 7.5
- CVE-2026-14976: IBM WebSphere Application Server Liberty RCE in collectiveControllerhighCVSS 7.1
- CVE-2026-16192: IBM WebSphere Application Server Liberty denial of service in restConnectorhighCVSS 7.1
- CVE-2026-11541: IBM WebSphere Application Server HTTP request smugglinghighCVSS 7.4
- CVE-2026-11806: IBM WebSphere Application Server Liberty arbitrary file read in restConnector-2.0highCVSS 7.2
- CVE-2026-11714: IBM WebSphere Application Server Liberty SSRF in apiDiscovery-1.0highCVSS 8.5
- CVE-2026-11546: IBM WebSphere Application Server Liberty SSRF in Admin CenterhighCVSS 7.1
- CVE-2026-10852: IBM WebSphere Application Server denial of service in WebServer Plug-inmediumCVSS 5.9
Most severe IBM WebSphere Application Server Liberty vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-14529: IBM WebSphere Application Server SSRF in SIP containercriticalCVSS 9.4
- CVE-2026-15325: IBM WebSphere Application Server HTTP request smuggling in TRACE requestshighCVSS 8.7
- CVE-2026-15064: IBM WebSphere Application Server HTTP response smugglinghighCVSS 8.7
- CVE-2026-11714: IBM WebSphere Application Server Liberty SSRF in apiDiscovery-1.0highCVSS 8.5
- CVE-2026-14980: IBM WebSphere Application Server Liberty CSRF in collectiveControllerhighCVSS 8.3
- CVE-2026-8400: IBM WebSphere Application Server arbitrary class instantiation via IIOPhighCVSS 8.1EPSS 0.5%
- CVE-2026-18499: IBM WebSphere Application Server Liberty privilege escalation in collectiveshighCVSS 8.1EPSS 0.4%
- CVE-2026-9072: IBM WebSphere WebServer Plug-in code injection in Intelligent ManagementhighCVSS 8.1
- CVE-2026-9322: IBM WebSphere Application Server denial of service via crafted HTTP requesthighCVSS 7.5
- CVE-2026-10842: IBM WebSphere Application Server security bypass in appSecurity featurehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 4 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 14 | 1 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/websphere-application-server-liberty.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM WebSphere Application Server Liberty vulnerabilities", https://junglewise.ai/threats/technologies/websphere-application-server-liberty, 26 September 2026.