CVE-2026-11536: IBM WebSphere Application Server is affected by a remote code execution vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Other sources
IBM WebSphere Application Server is affected by a remote code execution vulnerability in the SOAP/JMX connector.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71714
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11536?
The severity of CVE-2026-11536 is rated as high with a score of 8.5.
How do I fix CVE-2026-11536?
To fix CVE-2026-11536, upgrade to the latest patched version of IBM WebSphere Application Server.
What systems are affected by CVE-2026-11536?
CVE-2026-11536 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What type of vulnerability is CVE-2026-11536?
CVE-2026-11536 is a remote code execution vulnerability found in the SOAP/JMX connector.
What are the potential impacts of CVE-2026-11536?
The impacts of CVE-2026-11536 include unauthorized remote execution of code, which could compromise the entire application server.