CVE-2026-8633
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://www.ibm.com/support/pages/node/7274072
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | websphere_application_server | {"startIncluding":"8.5.0.0","endIncluding":"8.5.5.29"} | |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.