CVE-2026-8633: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty (8.5)to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty (9.0)to a version that resolves this vulnerability.Fixed in 9.0.5.28 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71342
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8633?
CVE-2026-8633 has a critical severity score of 9.8.
What systems are affected by CVE-2026-8633?
CVE-2026-8633 affects IBM WebSphere Application Server and WebSphere Liberty when using Web Server Plug-ins.
What type of vulnerability is CVE-2026-8633?
CVE-2026-8633 is a remote code execution vulnerability due to code injection.
How do I fix CVE-2026-8633?
To fix CVE-2026-8633, apply the currently available Web Server Plug-ins interim fix or fix pack that contains the fix for APAR PH71342.
What can happen if CVE-2026-8633 is exploited?
If exploited, CVE-2026-8633 can allow attackers to execute arbitrary code on the affected systems.