CVE-2026-11722: IBM WebSphere Application Server vulnerability
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Are specific affected versions identified?
No affected version numbers are provided in the available data. Review the IBM support reference for version-specific applicability and remediation guidance.
2
Does the available information describe exploit prerequisites or temporary mitigations?
No. The data identifies the issue as HTTP request smuggling but does not state attacker access requirements, configuration conditions, or compensating controls.