CVE-2026-8633
published 2026-05-26CVE-2026-8633: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.85%
54.3th percentile
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | web_server_plug-ins_for_websphere_application_server_and_websphere_liberty | — | — |
| ibm | websphere_application_server | 8.5.0.0 – 8.5.5.29 | — |
| ibm | websphere_application_server | 9.0.0.0 – 9.0.5.27 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty code injection (EUVD-2026-31927)
vuldb·2026-05-26·CVSS 9.8
CVE-2026-8633 [CRITICAL] IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty code injection (EUVD-2026-31927)
A vulnerability was found in IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5/9.0. It has been classified as critical. This affects an unknown part. The manipulation leads to code injection.
This vulnerability is documented as CVE-2026-8633. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-536c-j2qm-3hw6: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8
ghsa_unreviewed·2026-05-26
CVE-2026-8633 [CRITICAL] CWE-94 GHSA-536c-j2qm-3hw6: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
blogs_hackernews·2026-06-08·CVSS 8.4
CVE-2025-48595 [HIGH] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked.
A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again. And while everyone chased the loud stuff, quieter attackers sat in inboxes for months, reading mail and stealing it bit by bit.
Lots to cover. Grab coffee. Read up.
## ⚡ Threat of the Week
Miasma Worm Hits 73 Microsoft GitHub Repositories in Supply Chain
Bugzilla
CVE-2026-53369 kernel: udf: reject descriptors with oversized CRC length
bugzilla·2026-07-19·CVSS 8.4
CVE-2026-53369 [HIGH] CVE-2026-53369 kernel: udf: reject descriptors with oversized CRC length
CVE-2026-53369 kernel: udf: reject descriptors with oversized CRC length
In the Linux kernel, the following vulnerability has been resolved:
udf: reject descriptors with oversized CRC length
udf_read_tagged() skips CRC verification when descCRCLength +
sizeof(struct tag) exceeds the block size. A crafted UDF image can
set descCRCLength to an oversized value to bypass CRC validation
entirely; the descriptor is then accepted based solely on the 8-bit
tag checksum, which is trivially recomputable.
Reject such descriptors instead of silently accepting them. A
legitimate single-block descriptor should never have a CRC length that
exceeds the block.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026071918-CVE-2026-53369-8633@gregkh/T
2026-05-26
Published