Remote Code Execution in IBM WebSphere Application Server
CVE-2026-11536

8.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 July 2026

What is CVE-2026-11536?

IBM WebSphere Application Server versions 9.0 and 8.5 contain a vulnerability in the SOAP/JMX connector that could allow an attacker to execute arbitrary code remotely. This weakness exploits inadequate input validation, making it crucial for organizations utilizing these versions to apply the appropriate patches provided by IBM to mitigate potential threats.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.