CVE-2026-9006
IBM WebSphere Application Server, websphere application server, aix
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
- CVSS
- 9.1
- EPSS
- 0.22% 12.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23