CVE-2026-1561
published 2026-03-25CVE-2026-1561: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery…
PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.28%
20.6th percentile
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 17.0.0.3 < 26.0.0.4 | 26.0.0.4 |
| ibm | websphere_application_server_liberty | 17.0.0.3 – 26.0.0.3 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM WebSphere Application Server Liberty up to 26.0.0.3 server-side request forgery (Nessus ID 313186 / WID-SEC-2026-1687)
vuldb·2026-05-28·CVSS 5.4
CVE-2026-1561 [MEDIUM] IBM WebSphere Application Server Liberty up to 26.0.0.3 server-side request forgery (Nessus ID 313186 / WID-SEC-2026-1687)
A vulnerability labeled as critical has been found in IBM WebSphere Application Server Liberty up to 26.0.0.3. This affects an unknown function. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-1561. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-8gm5-jf6f-36wc: IBM WebSphere Application Server - Liberty 17
ghsa_unreviewed·2026-03-25
CVE-2026-1561 [MEDIUM] CWE-918 GHSA-8gm5-jf6f-36wc: IBM WebSphere Application Server - Liberty 17
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Red Hat
kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
vendor_redhat·2026-06-25·CVSS 5.5
CVE-2026-53163 [MEDIUM] CWE-476 kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
In the Linux kernel, the following vulnerability has been resolved:
locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:
KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
class_raw_spinlock_constructor
remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
rt_mutex_start_proxy_lock+0x103/0x120
futex_requeue+0x10e4/0x20d0
__x64_sys_futex+0x34f/0x4d0
task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.
Furthermore, rt_mutex_start_proxy_lock() should not
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
blogs_hackernews·2026-04-13·CVSS 8.6
[HIGH] ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game
Wiz
CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14915 [MEDIUM] CVE-2025-14915 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14915 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Source : NVD
## 7.2
Score
Published March 25, 2026
Severity HIGH
CNA Score 6.5
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH Has Fix Added at: Mar 31, 2026
Windows Severity HI
Wiz
CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14914 [MEDIUM] CVE-2025-14914 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14914 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.
Source : NVD
## 7.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 7.6
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity HIGH No Fix Added at: Feb 03, 2026
Windows Sev
Wiz
CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-13333 [MEDIUM] CVE-2025-13333 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13333 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings.
Source : NVD
## 4.9
Score
Published February 17, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity MEDIUM No Fix Added at: Feb 18, 2026
Windows Severity MEDIUM No Fix Added at: Feb 18, 2026
Linux Severity MEDIUM Has Fix Added at:
Wiz
CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14917 [MEDIUM] CVE-2025-14917 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14917 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
Source : NVD
## 9.8
Score
Published March 25, 2026
Severity CRITICAL
CNA Score 6.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 31, 2026
Windows Severity CRITICAL Has Fix Added
Wiz
CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-1561 [MEDIUM] CVE-2026-1561 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1561 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF). This may allow remote attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_applic
Wiz
CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-14923 [MEDIUM] CVE-2025-14923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14923 :
IBM WebSphere Application Server vulnerability analysis and mitigation
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Source : NVD
## 9.8
Score
Published March 3, 2026
Severity CRITICAL
CNA Score 4.7
Affected Technologies
IBM WebSphere Application Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ibm:websphere_application_server
Sources
Linux Severity CRITICAL Has Fix Added at: Mar 04, 2026
Windows Se
Bugzilla
CVE-2026-53163 kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
bugzilla·2026-06-25
CVE-2026-53163 [MEDIUM] CVE-2026-53163 kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53163 kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
In the Linux kernel, the following vulnerability has been resolved:
locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:
KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
class_raw_spinlock_constructor
remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
rt_mutex_start_proxy_lock+0x103/0x120
futex_requeue+0x10e4/0x20d0
__x64_sys_futex+0x34f/0x4d0
task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.
Furthermore, rt_mutex_start_pro
2026-03-25
Published