CVE-2026-14528: IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Other sources
IBM WebSphere Application Server traditional could allow a remote attacker to obtain sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72166
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14528?
The severity of CVE-2026-14528 is rated high with a score of 7.4.
How do I fix CVE-2026-14528?
To fix CVE-2026-14528, apply the recommended patches and updates from IBM for WebSphere Application Server.
What types of information can be exposed due to CVE-2026-14528?
CVE-2026-14528 can lead to exposure of sensitive information from the IBM WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-14528?
CVE-2026-14528 affects IBM WebSphere Application Server versions 9.0 and 8.5 traditional.
What attack vectors are associated with CVE-2026-14528?
CVE-2026-14528 can be exploited by a remote attacker with no authentication required to obtain sensitive information.