CVE-2026-14528Disclosure(ibm / websphere_application_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm websphere_application_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • websphere_application_server

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
websphere_application_server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-03: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-03: 108-03
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨Upozorňujeme na zranitelnosti v IBM WebSphere Application Server, CVE-2026-14512, CVE-2026-14446, CVE-2026-14529 a CVE-2026-14528. CVE-2026-14512 je zranitelnost způsobená nebezpečnou deserializací, která může vzdálenému neautentizovanému útočníkovi umožnit obejít autentizaci nebo spustit libovolný kód. CVE-2026-14446 je způsobená nesprávnou autentizací v administrační konzoli, která může útočníkovi umožnit získat zvýšená oprávnění. CVE-2026-14529 je vysoce závažná zranitelnost typu server-side request forgery, která se týká prostředí se zapnutou funkcí SIP container a při úspěšném zneužití může neautentizovanému útočníkovi umožnit odesílat speciálně vytvořené požadavky na interní systémy. CVE-2026-14528 je zranitelnost vedoucí k úniku citlivých informací prostřednictvím logovacích souborů. Úspěšné zneužití těchto zranitelností může vést ke spuštění libovolného kódu, eskalaci oprávnění, přístupu k citlivým informacím nebo provádění SSRF útoků. Zranitelnosti se týkají IBM WebSphere Application Server 9.0, IBM WebSphere Application Server 8.5 a IBM WebSphere Application Server Liberty ve verzích 17.0.0.3 až 26.0.0.8. 📌Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    The text announces multiple severe vulnerabilities in IBM WebSphere Application Server, detailing their types, affected versions, and potential impacts, and advises users to update to the latest release.

    12030740
    4.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmwebsphere_application_server---

Explore more