CVE-2026-9330
IBM WebSphere Application Server, websphere application server
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
- CVSS
- 8.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.06.02