CVE-2026-9006
published 2026-06-22CVE-2026-9006: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.22%
12.6th percentile
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | 8.5.0 – 7.0.3 Interim Fix 017 | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | websphere_application_server | 9.0 – 7.0.2 Interim Fix 035 | — |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured.
ghsa_unreviewed·2026-06-22
CVE-2026-9006 [HIGH] CWE-918 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the system, resulting in a security bypass or information disclosure.
VulDB
IBM WebSphere Application Server up to 8.5/9.0 server-side request forgery
vuldb·2026-06-22·CVSS 7.4
CVE-2026-9006 [HIGH] IBM WebSphere Application Server up to 8.5/9.0 server-side request forgery
A vulnerability was found in IBM WebSphere Application Server up to 8.5/9.0. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-9006. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published