CVE-2026-13773Patch(ibm / websphere_extreme_scale)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm websphere_extreme_scale systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • websphere_extreme_scale

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
websphere_extreme_scale

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 107-03
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo
    Patch

    ⚖️ IBM WebSphere eXtreme Scale 8.6.1.x has a critical SSRF flaw. ~50 CORBA stub classes in ogclient.jar call ORB.string_to_object() unsafely, enabling server-side request forgery. CVE-2026-13773 — patch if you're on 8.6.1.0-8.6.1.6. #IBM #cybersecurity https://secalerts.co/vulnerability/CVE-2026-13773?utm_campaign=x https://t.co/jlbC1tQGTQ

    Post summary

    The tweet discloses a critical SSRF flaw in IBM WebSphere eXtreme Scale 8.6.1.x, explains its technical vector, and supplies patch guidance for affected versions.

    0000072
    847 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmwebsphere_extreme_scale---

Explore more