cbcvebase.
CVE-2026-9311
published 2026-06-01

CVE-2026-9311: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server
ibmwebsphere_application_server9.0 – 1.1.9.12