CVE-2026-8400: Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
A flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Other sources
A flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantiation of arbitrary classes.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM SDK, Java Technology Edition bundled with IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch DT496796 - Upgrade
Upgrade
IBM SDK, Java Technology Edition Version 8 Service Refresh 8to a version that resolves this vulnerability.Fixed in 8 FP70
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8400?
CVE-2026-8400 has a severity rating of 8.1, classified as high.
How do I fix CVE-2026-8400?
To remediate CVE-2026-8400, apply the latest updates and patches provided by IBM for WebSphere Application Server and WebSphere Liberty.
What software is affected by CVE-2026-8400?
CVE-2026-8400 affects IBM WebSphere Application Server versions 8.5 and 9.0, as well as IBM WebSphere Application Server Liberty.
What type of vulnerability is CVE-2026-8400?
CVE-2026-8400 is a security vulnerability in the ORB component of IBM SDK that may allow arbitrary class loading.
Can CVE-2026-8400 be exploited remotely?
Yes, CVE-2026-8400 can be exploited remotely by a malicious IIOP server.