CVE-2026-16187: IBM WebSphere Application Server vulnerability
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker can exploit it by sending a crafted unauthenticated request; no prior authentication is indicated.
2
What could an attacker gain from successful exploitation?
Successful exploitation could bypass authentication and expose sensitive information.