IBM disclosed two vulnerabilities in traditional IBM WebSphere Application Server affecting versions 9.0 and 8.5, led by CVE-2026-14512, a pre-authentication unsafe deserialization flaw rated CVSS 9.8. The issue could allow a remote attacker to bypass authentication or achieve arbitrary code execution without user interaction, creating a high-risk path to full compromise of exposed WebSphere environments.
IBM also identified CVE-2026-14528, a CVSS 7.4 flaw that could expose sensitive information through insertion into log files. The company directed customers to apply the interim fix for APAR PH72166 or upgrade to Fix Pack 9.0.5.29+ for WebSphere 9.0 and Fix Pack 8.5.5.31+ for WebSphere 8.5, and said no workarounds or mitigations are available.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-28, IBM disclosed CVE-2026-14446 affecting traditional IBM WebSphere Application Server 8.5 and 9.0. The flaw was described as a critical broken access control and privilege escalation issue in the administrative console that could be exploited remotely without authentication.
On 2026-07-28, CVE-2026-14512 was recorded as affecting traditional IBM WebSphere Application Server versions 9.0 and 8.5. The vulnerability was described as a pre-authentication unsafe deserialization issue that could allow a remote attacker to bypass authentication or execute arbitrary code.
On 2026-07-28, IBM published a security bulletin for traditional IBM WebSphere Application Server 9.0 and 8.5 covering CVE-2026-14512, a pre-authentication unsafe deserialization flaw, and CVE-2026-14528, a sensitive information exposure issue. IBM recommended applying interim fix APAR PH72166 or upgrading to Fix Pack 9.0.5.29+ or 8.5.5.31+, and said no workarounds or mitigations were available.
On 2026-07-17, ACN/CSIRT Italia published a notice about a newly disclosed high-severity IBM WebSphere vulnerability that could let an attacker bypass authentication. The notice said affected products included traditional WebSphere Application Server 8.5.x before 8.5.5.31, 9.0.x before 9.0.5.29, and WebSphere Liberty from 17.0.0.3 up to but excluding 26.0.0.8, and advised updating per IBM guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceibm.com
Open sourcecvefeed.io
Open sourceacn.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.