Websphere application server
This hub aggregates every CVE we track for Websphere application server, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
501
CVEs tracked
53
Critical
110
High
1
In CISA KEV
Severity distribution
MEDIUM294HIGH110CRITICAL53LOW44
Monthly trend
1
3
2
0
0
0
0
1
1
1
1
5
1
0
0
1
0
2
4
1
4
20
21
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Websphere application server.
- CVE-2026-8400Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU8.1
- CVE-2026-11536IBM WebSphere Application Server is affected by a remote code execution vulnerability8.5
- CVE-2026-9322IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities7.5
- CVE-2026-10842IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability7.5
- CVE-2026-11897IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/27.5
- CVE-2026-14980IBM WebSphere Application Server Liberty is affected by a cross-site request forgery8.3
- CVE-2026-2482IBM WebSphere Application Server Liberty is affected by a cross-site request forgery3.1
- CVE-2026-14529IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery9.4
- CVE-2026-14446IBM WebSphere Application Server is affected by a privilege escalation9.8
- CVE-2026-14515IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities6.1
- CVE-2026-14512IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information9.8
- CVE-2026-14528IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information7.4
- CVE-2026-14974IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities8.1
- CVE-2026-14976IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability7.1
- CVE-2026-14981IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities7.5
Product normalization is registry-driven with AI assist and human review. How it works