CVE-2026-8633Disclosure(ibm / websphere_application_server)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch ibm websphere_application_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

5.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • websphere_application_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 4 mentions (2026-05-26); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
websphere_application_server

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-05-26: 4Mentions · 2026-05-28: 1Mentions · 2026-05-30: 1Mentions · 2026-06-01: 3Mentions · 2026-06-02: 2Mentions · 2026-06-08: 1Mentions · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-01: 1Active Exploitation · 2026-06-01: 2Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-02: 2Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 3Technical Details · 2026-06-02: 2Technical Details · 2026-06-08: 1Technical Details · 2026-06-14: 105-2605-2805-3006-0106-0206-0806-14
Signal classification4 categories
Disclosure
538.5%
Patch
430.8%
General
215.4%
Active Exploitation
215.4%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-264
Disclosure1General2Patch1
2026-05-281
Disclosure1
2026-05-301
Patch1
2026-06-013
Active Exploitation2Disclosure1
2026-06-022
Patch2
2026-06-081
Disclosure1
2026-06-141
Disclosure1
Full discourse13 posts
  • elhacker.NET@elhackernet
    Disclosure

    IBM WebSphere vulnerable a ejecución remota de código mediante solicitudes manipuladas CVE-2026-8633 https://blog.elhacker.net/2026/06/ibm-websphere-vulnerable-ejecucion.html

    Post summary

    A new remote code execution vulnerability (CVE-2026-8633) has been disclosed for IBM WebSphere, involving manipulated requests that can lead to code execution.

    08015112.1K
    140.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-8633 — CVSS 9.8/10 ██████████ IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/F91CB5N7IR

    Post summary

    IBM is alerting about CVE-2026-8633, a critical vulnerability (CVSS 9.8/10), and urges users to apply the patch immediately.

    20100153
    43 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    CVE-2026-8633 in IBM WebSphere is the kind of pre-patch advisory worth inventory time. Unauth network RCE against Web Server Plug-ins on Traditional + Liberty 8.5/9.0. IBM has the fix queued (APAR PH71342) but not yet in a Fix Pack. Now is when you map your WebSphere footprint, not when the PoC drops. https://purple-ops.io/blog/ibm-websphere-cve-2026-8633-rce

    Post summary

    The post highlights a pre‑patch unauthenticated remote‑code‑execution CVE‑2026‑8633 in IBM WebSphere plug‑ins, noting a queued fix and urging organizations to inventory affected servers now.

    01010168
    580 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    IBM WebSphere の脆弱性 CVE-2026-8633 が FIX:HTTP リクエストを介した RCE の可能性 https://iototsecnews.jp/2026/06/01/ibm-websphere-server-vulnerable-to-remote-code-execution-attack-via-crafted-request/ IBM WebSphere の問題は、オプション・コンポーネントである Web Server Plug-ins のコード生成制御の不備が原因となっています。脆弱性 CVE-2026-8633 は、Web サーバと App サーバ間でリクエストをルーティングするプラグイン処理における、外部からのデータに対する不十分な検証に起因します。 そのため、細工された HTTP リクエストを処理する際に、攻撃者に悪意のペイロード注入を許し、リモートからの任意のコード実行を招く恐れがあります。同時に、通信を操作される恐れのある、HTTP リクエスト・スマグリングの脆弱性 CVE-2026-8620 も修正されています。ご利用のチームは、ご注意ください。 #CVE20268633 #IBM #Vulnerability #WebSphere

    Post summary

    The article announces IBM WebSphere CVE-2026-8633, detailing a remote code execution flaw that allows malicious payload injection via crafted HTTP requests, and notes that the vulnerability has been fixed.

    01000161
    494 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-8633: IBM WebSphere Plug-ins Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04ll0Jj0

    Post summary

    The article appears to introduce and explain a new IBM WebSphere remote code execution vulnerability, outlining its implications and recommended response actions.

    0000042
    31 followersView on X
  • Daily Security Review@securitydailyr
    Patch

    IBM patched CVE-2026-8633 — CVSS 9.8 unauthenticated RCE in WebSphere Web Server Plug-ins. Affects WAS 8.5/9.0 and Liberty 8.5/9.0. No active exploitation confirmed. Fix Packs: 9.0.5.28 / 8.5.5.30. https://dailysecurityreview.com/resources/ibm-websphere-cve-2026-8633-cvss-9-8-no-auth-rce-flaw-patched-2/ #CyberSecurity #VulnerabilityManag https://t.co/bO75rffjiQ

    Post summary

    IBM released patches for CVE‑2026‑8633, a high‑severity unauthenticated RCE affecting WebSphere Web Server and Liberty; no active exploitation reported.

    0000054
    116 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical RCE vulnerability (CVE-2026-8633) found in IBM WebSphere Application Server. Immediate patching required to prevent potential exploits. Link: https://thedailytechfeed.com/critical-remote-code-execution-vulnerability-in-ibm-websphere-poses-major-threat-urgent-patch-advised/ #Cybersecurity #IBM #WebSphere #RCE #Vulnerability #CVE #Exploit #Patching #Security #Threat #Server #Middleware #Enterprise #ZeroDay #Infosec #Risk #Exposure #Breach #Mitigation #Update

    Post summary

    The post announces a critical RCE in IBM WebSphere and urges immediate patching, but provides no PoC, exploit code, or evidence of active exploitation.

    0000076
    354 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: IBM WebSphere unauth RCE CVE-2026-8633 (CVSS 9.8). Crafted HTTP request = web-tier code exec. 9 detections, 14 IOCs. https://intel.threadlinqs.com/threat/TL-2026-0650 #ThreatIntel https://t.co/OKMjxnaabW

    Post summary

    Threat intel indicates that IBM WebSphere CVE-2026-8633, an unauthenticated RCE, is actively exploited in the wild through crafted HTTP requests, with multiple detections and IOCs reported.

    0000072
    54 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: IBM WebSphere Plug-ins unauth RCE CVE-2026-8633 (CVSS 9.8) + HTTP smuggling. 9 detections, 14 IOCs. https://intel.threadlinqs.com/threat/TL-2026-0650 #ThreatIntel #RCE https://t.co/mebiKSDnzw

    Post summary

    IBM WebSphere Plug‑ins are exposed to a high‑severity unauthenticated RCE (CVE‑2026‑8633) with evidence of active exploitation, as indicated by multiple detections and IOCs reported by threat intel.

    0000083
    54 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【IBM WebSphereのWeb Server Plug-insに未認証RCE】 IBM WebSphere Application ServerおよびWebSphere LibertyのWeb Server Plug-insに、深刻な脆弱性が確認されました。CVE-2026-8633 は、細工したリクエストにより未認証でリモートコード実行につながる可能性があり、CVSS 9.8のクリティカルと評価されています。 あわせて、HTTPリクエストスマグリングの CVE-2026-8620 も確認されています。WebSphereは基幹系や業務システムで長期運用されていることが多く、パッチ適用に停止調整が必要なため、対応が遅れやすい点がリスクです。 利用組織は、Web Server Plug-insの利用有無、外部公開経路、WAF・リバースプロキシログ、5xx急増、異常ヘッダを確認すべきです。日本の大企業・公共・金融・製造業では、棚卸し漏れのWebSphere環境を優先確認する必要があります。 #サイバーセキュリティ #IBM #WebSphere #RCE #CVE #脆弱性管理 #基幹システム #SOC https://www.security-next.com/184994

    Post summary

    IBM WebSphere Web Server Plug‑ins are affected by critical unauthenticated RCE (CVE‑2026‑8633) with CVSS 9.8, along with a related HTTP smuggling flaw (CVE‑2026‑8620); vendors are unaware of patches or active exploitation, and organizations are urged to assess exposure and review logs.

    00000492
    3.7K followersView on X
  • Matthias Knäpper@knaepp
    Disclosure

    PH71342:MULTIPLE VULNERABILITIES IN THE WEBSPHERE WEBSERVER PLUG-IN (CVE-2026-8633,CVE-2026-8620) https://tinyurl.com/24vretzo

    Post summary

    The post announces two new CVEs (CVE-2026-8633, CVE-2026-8620) affecting the Websphere Webserver plug‑in, but provides no technical details or evidence of exploitation.

    0000075
    109 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8633 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vu… https://www.cve.org/CVERecord?id=CVE-2026-8633

    Post summary

    The text references a CVE record for IBM WebSphere but provides no technical details, mitigation, or evidence of exploitation.

    00000187
    57.5K followersView on X
  • Matthias Knäpper@knaepp
    General

    IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins (CVE-2026-8633, CVE-2026-8620) https://tinyurl.com/25uz5mx3

    Post summary

    The sentence notes that IBM WebSphere Application Server and Liberty are impacted by CVE-2026-8633 and CVE-2026-8620, but provides no further technical or exploit details.

    0000090
    109 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appibmwebsphere_application_server---
Appibmwebsphere_application_server---

Explore more