cbcvebase.
CVE-2026-8633
published 2026-05-26

CVE-2026-8633: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmweb_server_plug-ins_for_websphere_application_server_and_websphere_liberty
ibmwebsphere_application_server8.5.0.0 – 8.5.5.29
ibmwebsphere_application_server9.0.0.0 – 9.0.5.27