IBM disclosed multiple vulnerabilities in the optional Web Server Plug-ins used with WebSphere Application Server and WebSphere Liberty, including CVE-2026-8633, a critical unauthenticated code injection flaw rated CVSS 9.8, and CVE-2026-8620, an HTTP request smuggling issue rated CVSS 7.5. The bugs affect supported 8.5 and 9.0 plug-in branches that sit in front of back-end WebSphere servers on platforms including Apache HTTP Server, Microsoft IIS, and IBM HTTP Server, allowing specially crafted HTTP requests to bypass trust boundaries, reach internal application servers, and potentially achieve arbitrary code execution and full system compromise.
IBM said no workarounds or mitigations are available and directed customers to apply interim fixes or upgrade to fixed plug-in versions tied to APAR PH71342, later updated under PH71376. IBM support notices said fixes were released through Fix Central for affected 9.0.5.24-9.0.5.27 and 8.5.5.25-8.5.5.29 ranges, with permanent remediation targeted for inclusion in WebSphere Application Server 9.0.5.28 and 8.5.5.30. The combined disclosure raised concern that request smuggling could help attackers bypass perimeter controls before exploiting the RCE flaw in exposed enterprise deployments.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
IBM's support notice states downloadable fixes were released on 16 June 2026 for affected version ranges and records that IFPH71342 was superseded by IFPH71376 the same day. The notice also says these fixes are targeted for later inclusion in WebSphere Application Server 9.0.5.28 and 8.5.5.30.
IBM released patches and interim fixes under APAR PH71342 for supported 8.5.5 and 9.0.5 Web Server Plug-ins branches. The fixes were issued as the primary remediation path because IBM stated no mitigations or workarounds were available.
IBM disclosed two vulnerabilities affecting the optional Web Server Plug-ins for WebSphere Application Server and Liberty: CVE-2026-8620, an HTTP request smuggling flaw, and CVE-2026-8633, a critical remote code execution flaw. IBM said no workarounds were available and directed customers to interim fixes and fixed plug-in versions under APAR PH71342.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
ibm.com
Open sourceibm.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.