CRITICAL 9.4 NVD

CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Affected Products

References

Published: 2026-07-29 · Source: NVD · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-07-29 via NVD. Affected: ibm/websphere_application_server.

Risk Timeline

CVE Disclosed2026-07-29 · 5 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-14980IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerabHIGH8.3
CVE-2026-7769IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2HIGH8.1
CVE-2026-11897IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerabHIGH7.5
CVE-2026-16192IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affectedHIGH7.1
CVE-2026-16184IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bHIGH7.0
CVE-2026-1918IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2MEDIUM4.9
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.