ZeroHour

CVE-2026-8858

CVSS 3.1
8.8 high
EPSS
<1%p34
Published
()
Modified
Description

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.

Vendors
ibm
Products
i
Weakness
CWE-94
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.