CVE-2026-11708Patch(ibm / websphere_application_server)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm websphere_application_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • websphere_application_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
websphere_application_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-06: 2Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-06: 2Technical Details · 2026-07-06: 2Technical Details · 2026-07-13: 107-0607-13
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-07-062
Patch2
2026-07-131
Disclosure1
Full discourse3 posts
  • Clone Systems@CloneSystemsInc
    Patch

    IBM WebSphere Application Server has been hit by multiple critical cross site scripting vulnerabilities affecting the administrative console and integrated help system. The most severe flaws, CVE-2026-11712 and CVE-2026-11708, carry critical severity scores and could allow attackers to execute malicious scripts in an administrator’s browser session. That can open the door to stolen session data, unauthorized actions, and potential compromise of sensitive application server environments. For organizations running IBM WebSphere Application Server 8.5 or 9.0, this is not a patch to park in the someday pile. Administrative consoles are high value targets, and attackers know that access to management interfaces can create serious downstream risk. Organizations should apply IBM’s recommended interim fixes or fix packs, restrict access to administrative consoles, review logs for unusual activity, and confirm that vulnerable instances are not unnecessarily exposed. When the admin console becomes the attack surface, the risk is sitting right where the keys are kept. #IBMWebSphere #CVE202611712 #CVE202611708 #CrossSiteScripting #VulnerabilityManagement #PatchManagement #ApplicationSecurity #Cybersecurity #InfoSec #CyberRisk

    Post summary

    The post announces critical XSS vulnerabilities in IBM WebSphere Application Server’s admin console, outlines their severity and impact, and urges applying the vendor’s interim fixes and implementing access controls.

    0002092
    257 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    IBM WebSphere の脆弱性 CVE-2026-11712/11708/11595 が FIX:深刻な XSS 攻撃の可能性 https://iototsecnews.jp/2026/07/06/multiple-ibm-websphere-vulnerabilities-enable-xss-and-path-traversal-attacks/ 今回の脆弱性は、管理コンソールの統合ヘルプ・システムにおいて、入力されたデータの検証や無害化の処理が適切に行われていないことに起因します。 WebSphere Application Server のような広く使われているシステムでは、補助的な機能であっても検証漏れがあると、深刻な問題につながります。特に CVE-2026-11712/CVE-2026-11708 の XSS 脆弱性は、ユーザーからの入力をそのまま処理してしまうことで、不正なスクリプトの実行を許してしまいます。また、 CVE-2026-11595 のパス・トラバーサル問題も、ファイルパスの入力を適切に制限できていないことに原因があります。ご利用のチームは、ご注意ください。 #CVE202611595 #CVE202611708 #CVE202611712 #IBM #Vulnerability #WebSphere

    Post summary

    The post announces several IBM WebSphere vulnerabilities (CVE-2026-11712, CVE-2026-11708, CVE-2026-11595) that enable XSS and path traversal due to inadequate input validation, but it contains no PoC, exploit, active exploitation evidence, or patch information.

    00000162
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    Critical IBM WebSphere flaws expose servers to XSS and path traversal - Three vulnerabilities in the admin console's help system include two rated critical (CVSS 9.3), affecting WebSphere 9.0 and 8.5 deployments. ⚠️ Admin takeover risk: The XSS flaws (CVE-2026-11712, CVE-2026-11708) let unauthenticated attackers inject scripts via crafted URLs. and since the console runs with elevated privileges, session hijacking could cascade into full server compromise. 🔧 Don't wait for fix packs: IBM urges applying interim fix APAR PH71756 immediately, as official fix packs (9.0.5.29 / 8.5.5.31) aren't due until Q3 2026.

    Post summary

    IBM exposes critical XSS and path traversal flaws in WebSphere admin console that could allow full server compromise, and urges users to apply interim APAR PH71756 before official fix packs arrive.

    0000052
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmwebsphere_application_server---

Explore more