{"schema_version":1,"title":"IBM WebSphere Application Server vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 62 vulnerabilities in IBM WebSphere Application Server: 0 in the last 7 days and 47 in the last 90 days, 10 of them critical and 1 exploited in the wild. The most recent, CVE-2026-11722, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/websphere-application-server","json_url":"https://junglewise.ai/threats/technologies/websphere-application-server.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/websphere-application-server","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":21,"all_time":62,"critical":10,"exploited":1,"last_7_days":0,"last_30_days":25,"last_90_days":47,"last_365_days":61},"latest":[{"cve":"CVE-2026-11722","cvss":4.8,"epss":0.0018,"slug":"cve-2026-11722-ibm-websphere-application-server-and-websphere-application-server","title":"IBM WebSphere Application Server HTTP request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:03.02+00:00","url":"https://junglewise.ai/threats/cve-2026-11722-ibm-websphere-application-server-and-websphere-application-server"},{"cve":"CVE-2026-11711","cvss":6.5,"epss":0.0038,"slug":"cve-2026-11711-ibm-websphere-application-server-9-0-and-8-5-is-affected-by-a","title":"IBM WebSphere Application Server deserialization vulnerability in Name Service","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:01.28+00:00","url":"https://junglewise.ai/threats/cve-2026-11711-ibm-websphere-application-server-9-0-and-8-5-is-affected-by-a"},{"cve":"CVE-2026-11710","cvss":6.5,"epss":0.0023,"slug":"cve-2026-11710-ibm-websphere-application-server-8-5-is-affected-by-an-http","title":"IBM WebSphere Application Server HTTP request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:01.097+00:00","url":"https://junglewise.ai/threats/cve-2026-11710-ibm-websphere-application-server-8-5-is-affected-by-an-http"},{"cve":"CVE-2026-11549","cvss":6.5,"epss":0.0023,"slug":"cve-2026-11549-ibm-websphere-application-server-and-websphere-application-server","title":"IBM WebSphere Application Server virtual host bypass","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:00.923+00:00","url":"https://junglewise.ai/threats/cve-2026-11549-ibm-websphere-application-server-and-websphere-application-server"},{"cve":"CVE-2026-11548","cvss":4.8,"epss":0.0018,"slug":"cve-2026-11548-ibm-websphere-application-server-and-websphere-application-server","title":"IBM WebSphere Application Server HTTP request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:00.783+00:00","url":"https://junglewise.ai/threats/cve-2026-11548-ibm-websphere-application-server-and-websphere-application-server"},{"cve":"CVE-2026-11540","cvss":5.3,"epss":0.003,"slug":"cve-2026-11540-ibm-websphere-application-server-9-0-and-8-5-could-allow-a-remote","title":"IBM WebSphere Application Server information disclosure in FileTransfer servlet","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:00.493+00:00","url":"https://junglewise.ai/threats/cve-2026-11540-ibm-websphere-application-server-9-0-and-8-5-could-allow-a-remote"},{"cve":"CVE-2026-11539","cvss":5.3,"epss":0.003,"slug":"cve-2026-11539-ibm-websphere-application-server-9-0-and-8-5-is-affected-by-an","title":"IBM WebSphere Application Server authentication bypass in SOAP/JMX connector","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:00.34+00:00","url":"https://junglewise.ai/threats/cve-2026-11539-ibm-websphere-application-server-9-0-and-8-5-is-affected-by-an"},{"cve":"CVE-2026-11537","cvss":4.3,"epss":0.0019,"slug":"cve-2026-11537-ibm-websphere-application-server-9-0-and-8-5-could-allow-a-remote","title":"IBM WebSphere Application Server information disclosure via FileTransfer servlet","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:05.893+00:00","url":"https://junglewise.ai/threats/cve-2026-11537-ibm-websphere-application-server-9-0-and-8-5-could-allow-a-remote"},{"cve":"CVE-2026-10841","cvss":4.2,"epss":0.0016,"slug":"cve-2026-10841-ibm-websphere-application-server-http-request-smuggling","title":"IBM WebSphere Application Server HTTP request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T16:17:05.027+00:00","url":"https://junglewise.ai/threats/cve-2026-10841-ibm-websphere-application-server-http-request-smuggling"},{"cve":"CVE-2026-16435","cvss":5.9,"epss":0.0031,"slug":"cve-2026-16435-ibm-websphere-application-server-authentication-bypass-in-xd","title":"IBM WebSphere Application Server authentication bypass in XD/Intelligent-Management","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:40.79+00:00","url":"https://junglewise.ai/threats/cve-2026-16435-ibm-websphere-application-server-authentication-bypass-in-xd"},{"cve":"CVE-2026-16190","cvss":3.1,"epss":0.0016,"slug":"cve-2026-16190-ibm-websphere-application-server-authorization-bypass","title":"IBM WebSphere Application Server authorization bypass","severity":"low","exploited":false,"published_at":"2026-09-14T20:16:40.143+00:00","url":"https://junglewise.ai/threats/cve-2026-16190-ibm-websphere-application-server-authorization-bypass"},{"cve":"CVE-2026-16189","cvss":4.8,"epss":0.0022,"slug":"cve-2026-16189-ibm-websphere-application-server-log-injection","title":"IBM WebSphere Application Server log injection","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:40.02+00:00","url":"https://junglewise.ai/threats/cve-2026-16189-ibm-websphere-application-server-log-injection"},{"cve":"CVE-2026-16188","cvss":5.3,"epss":0.0028,"slug":"cve-2026-16188-ibm-websphere-application-server-log-injection-vulnerability","title":"IBM WebSphere Application Server log injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:39.887+00:00","url":"https://junglewise.ai/threats/cve-2026-16188-ibm-websphere-application-server-log-injection-vulnerability"},{"cve":"CVE-2026-16187","cvss":6.5,"epss":0.0025,"slug":"cve-2026-16187-ibm-websphere-application-server-authentication-bypass-in-admin","title":"IBM WebSphere Application Server authentication bypass in admin console","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:39.757+00:00","url":"https://junglewise.ai/threats/cve-2026-16187-ibm-websphere-application-server-authentication-bypass-in-admin"},{"cve":"CVE-2026-16186","cvss":5.4,"epss":0.0018,"slug":"cve-2026-16186-ibm-websphere-application-server-reflected-cross-site-scripting","title":"IBM WebSphere Application Server reflected cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:39.623+00:00","url":"https://junglewise.ai/threats/cve-2026-16186-ibm-websphere-application-server-reflected-cross-site-scripting"},{"cve":"CVE-2026-16185","cvss":6.4,"epss":0.002,"slug":"cve-2026-16185-ibm-websphere-application-server-authentication-bypass-in-admin","title":"IBM WebSphere Application Server authentication bypass in admin console servlet","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-16185-ibm-websphere-application-server-authentication-bypass-in-admin"},{"cve":"CVE-2026-15887","cvss":5.4,"epss":0.0018,"slug":"cve-2026-15887-ibm-websphere-application-server-blind-server-side-request","title":"IBM WebSphere Application Server blind server-side request forgery in SOAP","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:38.663+00:00","url":"https://junglewise.ai/threats/cve-2026-15887-ibm-websphere-application-server-blind-server-side-request"},{"cve":"CVE-2026-15634","cvss":6.5,"epss":0.0025,"slug":"cve-2026-15634-ibm-websphere-application-server-http-request-smuggling-via","title":"IBM WebSphere Application Server HTTP request smuggling via transfer-encoding header","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:38.54+00:00","url":"https://junglewise.ai/threats/cve-2026-15634-ibm-websphere-application-server-http-request-smuggling-via"},{"cve":"CVE-2026-15412","cvss":6.5,"epss":0.0023,"slug":"cve-2026-15412-ibm-websphere-application-server-open-redirect-phishing-attack","title":"IBM WebSphere Application Server open redirect phishing attack","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:38.287+00:00","url":"https://junglewise.ai/threats/cve-2026-15412-ibm-websphere-application-server-open-redirect-phishing-attack"},{"cve":"CVE-2026-15396","cvss":6.5,"epss":0.0025,"slug":"cve-2026-15396-ibm-websphere-application-server-http-request-smuggling-via","title":"IBM WebSphere Application Server HTTP request smuggling via transfer-encoding","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:38.153+00:00","url":"https://junglewise.ai/threats/cve-2026-15396-ibm-websphere-application-server-http-request-smuggling-via"},{"cve":"CVE-2026-9667","cvss":5.3,"epss":0.0043,"slug":"cve-2026-9667-ibm-websphere-application-server-server-side-request-forgery","title":"IBM WebSphere Application Server server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-10T21:17:54.59+00:00","url":"https://junglewise.ai/threats/cve-2026-9667-ibm-websphere-application-server-server-side-request-forgery"},{"cve":"CVE-2026-9327","cvss":6.3,"epss":0.0037,"slug":"cve-2026-9327-ibm-websphere-application-server-privilege-escalation-in-security","title":"IBM WebSphere Application Server privilege escalation in security configuration","severity":"medium","exploited":false,"published_at":"2026-09-10T21:17:54.467+00:00","url":"https://junglewise.ai/threats/cve-2026-9327-ibm-websphere-application-server-privilege-escalation-in-security"},{"cve":"CVE-2026-9176","cvss":6.7,"epss":0.0016,"slug":"cve-2026-9176-ibm-websphere-application-server-authentication-bypass","title":"IBM WebSphere Application Server authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-10T21:17:54.22+00:00","url":"https://junglewise.ai/threats/cve-2026-9176-ibm-websphere-application-server-authentication-bypass"},{"cve":"CVE-2026-9338","cvss":5.3,"epss":0.0049,"slug":"cve-2026-9338-ibm-websphere-application-server-denial-of-service-via-crafted","title":"IBM WebSphere Application Server denial of service via crafted request","severity":"medium","exploited":false,"published_at":"2026-09-10T19:17:42.807+00:00","url":"https://junglewise.ai/threats/cve-2026-9338-ibm-websphere-application-server-denial-of-service-via-crafted"},{"cve":"CVE-2026-9336","cvss":6.5,"epss":0.0077,"slug":"cve-2026-9336-ibm-websphere-application-server-denial-of-service-via-http","title":"IBM WebSphere Application Server denial of service via HTTP request","severity":"medium","exploited":false,"published_at":"2026-09-10T19:17:42.68+00:00","url":"https://junglewise.ai/threats/cve-2026-9336-ibm-websphere-application-server-denial-of-service-via-http"}],"weekly":[{"week":"2026-06-29","critical":2,"exploited":0,"vulnerabilities":5},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":4,"exploited":0,"vulnerabilities":15},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":20},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"},{"name":"IBM Db2","slug":"db2","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/db2"},{"name":"IBM Mq","slug":"mq","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM Verify Identity Access","slug":"verify-identity-access","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/verify-identity-access"},{"name":"IBM Power Systems Firmware","slug":"power-systems-firmware","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/power-systems-firmware"}],"technology":{"hub":true,"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"application-server","homepage":"https://www.ibm.com/products/websphere-application-server","description":"A Java Enterprise Edition application server used for hosting and managing enterprise web applications.","url":"https://junglewise.ai/threats/technologies/websphere-application-server"},"most_severe":[{"cve":"CVE-2015-7450","cvss":9.8,"slug":"cve-2015-7450-ibm-websphere-application-server-and-server-hypervisor-edition","title":"IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.","severity":"critical","exploited":true,"published_at":"2022-01-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-7450-ibm-websphere-application-server-and-server-hypervisor-edition"},{"cve":"CVE-2026-14512","cvss":9.8,"slug":"cve-2026-14512-ibm-websphere-application-server-unsafe-deserialization","title":"IBM WebSphere Application Server unsafe deserialization","severity":"critical","exploited":false,"published_at":"2026-07-28T21:17:25.783+00:00","url":"https://junglewise.ai/threats/cve-2026-14512-ibm-websphere-application-server-unsafe-deserialization"},{"cve":"CVE-2026-14446","cvss":9.8,"slug":"cve-2026-14446-ibm-websphere-application-server-privilege-escalation-in","title":"IBM WebSphere Application Server privilege escalation in administrative console","severity":"critical","exploited":false,"published_at":"2026-07-28T21:17:25.66+00:00","url":"https://junglewise.ai/threats/cve-2026-14446-ibm-websphere-application-server-privilege-escalation-in"},{"cve":"CVE-2026-14529","cvss":9.4,"slug":"cve-2026-14529-ibm-websphere-application-server-ssrf-in-sip-container","title":"IBM WebSphere Application Server SSRF in SIP container","severity":"critical","exploited":false,"published_at":"2026-07-29T19:16:44.72+00:00","url":"https://junglewise.ai/threats/cve-2026-14529-ibm-websphere-application-server-ssrf-in-sip-container"},{"cve":"CVE-2026-11707","cvss":9.3,"slug":"cve-2026-11707-ibm-websphere-application-server-xss-in-administrative-console","title":"IBM WebSphere Application Server XSS in administrative console login page","severity":"critical","exploited":false,"published_at":"2026-07-30T15:16:24.01+00:00","url":"https://junglewise.ai/threats/cve-2026-11707-ibm-websphere-application-server-xss-in-administrative-console"},{"cve":"CVE-2026-11712","cvss":9.3,"slug":"cve-2026-11712-ibm-websphere-application-server-xss-in-administrative-console","title":"IBM WebSphere Application Server XSS in administrative console help system","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:27.897+00:00","url":"https://junglewise.ai/threats/cve-2026-11712-ibm-websphere-application-server-xss-in-administrative-console"},{"cve":"CVE-2026-11708","cvss":9.3,"slug":"cve-2026-11708-ibm-websphere-application-server-xss-in-administrative-console","title":"IBM WebSphere Application Server XSS in administrative console help system","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:27.767+00:00","url":"https://junglewise.ai/threats/cve-2026-11708-ibm-websphere-application-server-xss-in-administrative-console"},{"cve":"CVE-2026-8644","cvss":9.1,"slug":"cve-2026-8644-ibm-websphere-application-server-identity-spoofing-authentication","title":"IBM WebSphere Application Server identity spoofing authentication bypass","severity":"critical","exploited":false,"published_at":"2026-06-01T19:16:55.097+00:00","url":"https://junglewise.ai/threats/cve-2026-8644-ibm-websphere-application-server-identity-spoofing-authentication"},{"cve":"CVE-2026-9319","cvss":9,"slug":"cve-2026-9319-ibm-websphere-application-server-remote-code-execution-in-jax-ws","title":"IBM WebSphere Application Server remote code execution in JAX-WS","severity":"critical","exploited":false,"published_at":"2026-06-01T19:16:55.68+00:00","url":"https://junglewise.ai/threats/cve-2026-9319-ibm-websphere-application-server-remote-code-execution-in-jax-ws"},{"cve":"CVE-2026-9311","cvss":9,"slug":"cve-2026-9311-ibm-websphere-application-server-remote-code-execution-via","title":"IBM WebSphere Application Server remote code execution via security bypass","severity":"critical","exploited":false,"published_at":"2026-06-01T19:16:55.537+00:00","url":"https://junglewise.ai/threats/cve-2026-9311-ibm-websphere-application-server-remote-code-execution-via"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}