CVE-2026-9072: WebSphere Application Server Remote Code Execution
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Web Server Plug-ins (Intelligent Management with WebSphere WebServer Plug-in component)to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server Web Server Plug-ins (Intelligent Management with WebSphere WebServer Plug-in component)to a version that resolves this vulnerability.Fixed in 9.0.5.28 - Upgrade
Upgrade
IBM WebSphere Application Server Web Server Plug-ins (Intelligent Management with WebSphere WebServer Plug-in component)to a version that resolves this vulnerability.Patch PH71376
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9072?
The severity of CVE-2026-9072 is rated as critical, with a score of 9.8.
How can I mitigate CVE-2026-9072?
To mitigate CVE-2026-9072, ensure that your IBM WebSphere Application Server is updated to the latest version and follow the security patches provided by IBM.
What types of vulnerabilities are associated with CVE-2026-9072?
CVE-2026-9072 includes vulnerabilities for denial of service, HTTP request smuggling, and remote code execution.
Who is affected by CVE-2026-9072?
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty users, specifically those using Intelligent Management with the WebSphere WebServer Plug-in, are affected by CVE-2026-9072.
What potential impact does CVE-2026-9072 have on systems?
CVE-2026-9072 can potentially lead to remote code execution and denial of service, compromising the security of the affected systems.