Multiple IBM WebSphere critical security vulnerabilities published over the past several months are now being publicly exploited to compromise systems. The vulnerabilities could allow for remote command execution, privilege escalation, and exposure of sensitive information.
Vulnerability Details
CVEs: CVE-2026-9330, CVE-2026-9311, CVE-2026-14512, CVE-2026-14528, CVE-2026-11545
CVSS 3.1 score: 3.7 – 9.8 (Critical)
Disclosed: June 2026 – September 2026
Exploit Status: Public exploitation has been observed across multiple WebSphere environments including attempts to infiltrate UCLA environments
Recommendation
Information Security is advising all campus WebSphere service owners to contact IBM for the latest hotfix and schedule emergency maintenance to patch platforms against these critical vulnerabilities.
Vendor Security Bulletins