CRITICAL 9.4 NVD
CVE-2026-14529
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Affected Products
- ibm/websphere_application_server
References
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-07-29 via NVD. Affected: ibm/websphere_application_server.
Risk Timeline
CVE Disclosed2026-07-29 · 5 days ago
Remediation Resources
Analysis & PoC
www.ibm.com/support/pages/node/7281721Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-14980 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerab | HIGH | 8.3 |
| CVE-2026-7769 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2 | HIGH | 8.1 |
| CVE-2026-11897 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab | HIGH | 7.5 |
| CVE-2026-16192 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected | HIGH | 7.1 |
| CVE-2026-16184 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b | HIGH | 7.0 |
| CVE-2026-1918 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2 | MEDIUM | 4.9 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.