Skip to Main Content

IBM WebSphere Vulnerability Advisory (Sept 2026)

Multiple IBM WebSphere critical security vulnerabilities published over the past several months are now being publicly exploited to compromise systems. The vulnerabilities could allow for remote command execution, privilege escalation, and exposure of sensitive information.

Vulnerability Details

CVEs: CVE-2026-9330, CVE-2026-9311, CVE-2026-14512, CVE-2026-14528, CVE-2026-11545

CVSS 3.1 score: 3.7 – 9.8 (Critical)

Disclosed: June 2026 – September 2026

Exploit Status: Public exploitation has been observed across multiple WebSphere environments including attempts to infiltrate UCLA environments

Recommendation

Information Security is advising all campus WebSphere service owners to contact IBM for the latest hotfix and schedule emergency maintenance to patch platforms against these critical vulnerabilities.

Vendor Security Bulletins

https://www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-affected-remote-code-execution-cve-2026-9311-cve-2026-9330

https://www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-affected-unsafe-deserialization-and-exposure-sensitive-information-cve-2026-14512-cve-2026-14528

https://www.ibm.com/support/pages/node/7286730