IBM disclosed multiple vulnerabilities in WebSphere Application Server and WebSphere Application Server Liberty, including denial-of-service issues tracked as CVE-2026-9071 and CVE-2026-9320, and an HTTP request smuggling flaw, CVE-2026-8646, rated up to CVSS 8.1. The affected products include WebSphere Application Server 8.5 and 9.0, along with WebSphere Liberty versions 17.0.0.3 through 26.0.0.6 when certain servlet or websocket features are enabled. IBM said no workarounds or mitigations are available and advised customers to apply interim fixes for APAR PH71631 and PH71370 or upgrade to fix packs 26.0.0.7, 9.0.5.29, or 8.5.5.30.
A related high-severity issue, CVE-2026-9072, affects IBM i 7.3 through 7.6 in environments using WebSphere Application Server or Liberty with Intelligent Management and the WebSphere WebServer Plug-in. IBM said an attacker who can impersonate backend servers and send crafted responses to the plug-in could trigger remote code execution and denial of service, also with a CVSS 8.1 rating. Recommended actions include installing the latest WebSphere security updates, updating IBM i to current levels, and reviewing the secure configuration of Intelligent Management and the WebSphere WebServer Plug-in.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A high-severity entry for CVE-2026-9072 described IBM i 7.3 through 7.6 deployments using WebSphere Application Server or WebSphere Application Server Liberty with Intelligent Management and the WebSphere WebServer Plug-in as vulnerable. The flaw can enable remote code execution and denial of service via crafted responses from an attacker impersonating backend servers, and the advisory recommended applying IBM security updates and updating IBM i.
IBM published a security bulletin disclosing CVE-2026-9071, CVE-2026-9320, and CVE-2026-8646 affecting WebSphere Application Server and WebSphere Application Server Liberty, including denial-of-service and HTTP request smuggling issues. IBM said affected products should receive interim fixes or upcoming fix packs and noted no workarounds or mitigations were available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.