CVE-2026-11712Patch(ibm / websphere_application_server)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm websphere_application_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • websphere_application_server

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
websphere_application_server

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-06-30: 1Mentions · 2026-07-06: 3Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-06: 3Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-06: 3Technical Details · 2026-07-13: 106-3007-0607-13
Signal classification2 categories
Patch
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-301
General1
2026-07-063
Patch3
2026-07-131
Patch1
Full discourse5 posts
  • Aretiq.AI@AretiqAI
    General

    ARETIQ Daily Vulnerability Bulletin — June 30, 2026 🟣 EMERGENCY: CVE-2026-48282 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48281 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48283 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48277 (adobe/coldfusion) AAS 16.3 🟣 EMERGENCY: CVE-2026-48276 (adobe/coldfusion) AAS 16.3 🔴 CRITICAL: CVE-2026-48315 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48313 (adobe/coldfusion) AAS 14.9 🔴 CRITICAL: CVE-2026-48307 (adobe/coldfusion) AAS 13.9 🔴 CRITICAL: CVE-2026-48285 (adobe/coldfusion) AAS 13.5 🔴 CRITICAL: CVE-2026-11712 (ibm/websphere_application_server) AAS 14.9 + 9 more CRITICAL 31 vulnerabilities — EMERGENCY: 5, CRITICAL: 14, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-30/

    Post summary

    The bulletin lists several Adobe ColdFusion and IBM WebSphere CVEs with severity scores but provides no PoC, exploit, active exploitation, mitigation, or detailed technical content.

    010111689
    227 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    IBM WebSphere vulnerabilities like CVE-2026-11712 expose servers to severe XSS and path traversal attacks. Patch systems immediately. #IBM #WebSphere #CyberSecurity #CVE202611712 http://securityonline.info/ibm-websphere-vulnerabilities/

    Post summary

    IBM WebSphere CVE‑2026‑11712 is identified as a severe XSS and path traversal flaw, and the post urges administrators to patch affected systems immediately.

    01011711
    12.9K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    IBM WebSphere Application Server has been hit by multiple critical cross site scripting vulnerabilities affecting the administrative console and integrated help system. The most severe flaws, CVE-2026-11712 and CVE-2026-11708, carry critical severity scores and could allow attackers to execute malicious scripts in an administrator’s browser session. That can open the door to stolen session data, unauthorized actions, and potential compromise of sensitive application server environments. For organizations running IBM WebSphere Application Server 8.5 or 9.0, this is not a patch to park in the someday pile. Administrative consoles are high value targets, and attackers know that access to management interfaces can create serious downstream risk. Organizations should apply IBM’s recommended interim fixes or fix packs, restrict access to administrative consoles, review logs for unusual activity, and confirm that vulnerable instances are not unnecessarily exposed. When the admin console becomes the attack surface, the risk is sitting right where the keys are kept. #IBMWebSphere #CVE202611712 #CVE202611708 #CrossSiteScripting #VulnerabilityManagement #PatchManagement #ApplicationSecurity #Cybersecurity #InfoSec #CyberRisk

    Post summary

    IBM WebSphere Application Server faces critical XSS vulnerabilities (CVE‑2026‑11712, CVE‑2026‑11708); the post outlines the exploit potential and urges users to apply IBM’s interim fixes or fix packs and secure the administrative console.

    0002092
    257 followersView on X
  • iototsecnews@iototsecnews
    Patch

    IBM WebSphere の脆弱性 CVE-2026-11712/11708/11595 が FIX:深刻な XSS 攻撃の可能性 https://iototsecnews.jp/2026/07/06/multiple-ibm-websphere-vulnerabilities-enable-xss-and-path-traversal-attacks/ 今回の脆弱性は、管理コンソールの統合ヘルプ・システムにおいて、入力されたデータの検証や無害化の処理が適切に行われていないことに起因します。 WebSphere Application Server のような広く使われているシステムでは、補助的な機能であっても検証漏れがあると、深刻な問題につながります。特に CVE-2026-11712/CVE-2026-11708 の XSS 脆弱性は、ユーザーからの入力をそのまま処理してしまうことで、不正なスクリプトの実行を許してしまいます。また、 CVE-2026-11595 のパス・トラバーサル問題も、ファイルパスの入力を適切に制限できていないことに原因があります。ご利用のチームは、ご注意ください。 #CVE202611595 #CVE202611708 #CVE202611712 #IBM #Vulnerability #WebSphere

    Post summary

    The post announces that IBM WebSphere CVE‑2026‑11712, CVE‑2026‑11708, and CVE‑2026‑11595 have been fixed, highlighting that the flaws enable XSS and path‑traversal attacks.

    00000162
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    Critical IBM WebSphere flaws expose servers to XSS and path traversal - Three vulnerabilities in the admin console's help system include two rated critical (CVSS 9.3), affecting WebSphere 9.0 and 8.5 deployments. ⚠️ Admin takeover risk: The XSS flaws (CVE-2026-11712, CVE-2026-11708) let unauthenticated attackers inject scripts via crafted URLs. and since the console runs with elevated privileges, session hijacking could cascade into full server compromise. 🔧 Don't wait for fix packs: IBM urges applying interim fix APAR PH71756 immediately, as official fix packs (9.0.5.29 / 8.5.5.31) aren't due until Q3 2026.

    Post summary

    The post emphasizes critical WebSphere admin console flaws and urges immediate application of an interim fix APAR PH71756 while awaiting official patches.

    0000052
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmwebsphere_application_server---

Explore more