CVE-2026-9072
IBM WebSphere Application Server, i
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
- CVSS
- 9.8
- EPSS
- 0.41% 33.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23