Remote Code Execution Vulnerability in IBM WebSphere Application Server
CVE-2026-9072

8.1HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-9072?

A security flaw exists in IBM WebSphere Application Server versions 7.6, 7.5, 7.4, and 7.3, as well as IBM WebSphere Application Server Liberty, when utilizing Intelligent Management with the WebSphere WebServer Plug-in. This vulnerability allows attackers to execute remote code or cause a denial of service by impersonating backend servers and sending crafted responses to the vulnerable plug-in, potentially compromising system integrity and availability. Users are advised to apply the recommended patches promptly to secure their systems.

Affected Version(s)

i 7.6.0 <= 1.8.4

i 7.5.0

i 7.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.