IBM disclosed multiple high-severity vulnerabilities affecting WebSphere and webMethods Integration Server, exposing enterprise middleware environments to remote compromise. In WebSphere, the reported issues include remote code execution flaws tracked as CVE-2026-9311, CVE-2026-9330, and CVE-2026-9319, alongside an authentication bypass and identity spoofing issue, CVE-2026-8644. Affected deployments include traditional WebSphere versions 9.0 and 8.5, with IBM issuing interim fixes through specific APARs and urging administrators to verify configurations and apply patches quickly.
A separate IBM advisory covers webMethods Integration Server CVE-2025-36072, a deserialization-based remote code execution flaw that can be exploited by an authenticated attacker with service execution privileges through internal APIs or protocols such as IDataBin. The vulnerability affects versions 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 if they have not received the latest core fixes. Successful exploitation could allow arbitrary code execution in the Integration Server process, enabling lateral movement, persistence, and data exfiltration across business-critical systems.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
IBM disclosed multiple high-severity vulnerabilities affecting WebSphere, including remote code execution issues CVE-2026-9311, CVE-2026-9330, and CVE-2026-9319, plus authentication bypass and identity spoofing flaw CVE-2026-8644. The company issued interim fixes via APARs for affected traditional WebSphere versions 9.0 and 8.5.
ZeroPath reported on CVE-2025-36072, a remote code execution vulnerability in IBM webMethods Integration Server caused by unsafe deserialization and affecting multiple 10.11, 10.15, and 11.1 builds without the latest core fixes. The report said no public proof-of-concept details were available and that exploitation required authentication and service execution privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.