Remote Code Execution Vulnerability in IBM WebSphere Application Server
CVE-2026-9319

9CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
1 June 2026

What is CVE-2026-9319?

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to remote code execution risks stemming from the deserialization of untrusted data through JAX-WS endpoints that utilize WS-Security. This vulnerability may allow attackers to execute arbitrary code on the server, potentially compromising sensitive information and system integrity. Administrators are advised to review the vendor's security advisory and apply the necessary patches promptly.

Affected Version(s)

WebSphere Application Server 9.0 <= 1.1.9.12

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.