German security advisories reported multiple vulnerabilities in IBM WebSphere Application Server Liberty, including a flaw that could allow attackers to bypass security measures. The notices identify at least two separate issues affecting the Liberty application server platform, indicating ongoing security concerns for organizations running IBM middleware in production environments.
The advisories describe one case as a security bypass vulnerability and another as multiple vulnerabilities, suggesting that affected deployments may face a range of risks depending on configuration and exposure. Organizations using IBM WebSphere Liberty should review IBM and national CERT guidance, determine affected versions, and prioritize patching or other mitigations to reduce the risk of unauthorized access or compromise.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
dCERT published Advisory 2026-1214 for IBM WebSphere Application Server describing a vulnerability that allows bypassing security measures. This appears to be a separate disclosure from earlier IBM WebSphere Liberty advisories.
dCERT published Advisory 2026-0830 for IBM WebSphere Application Server Liberty covering multiple vulnerabilities.
dCERT published Advisory 2026-0512 for IBM WebSphere Application Server Liberty describing a vulnerability that allows bypassing security measures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.