CVE-2026-8633

CRITICAL WAF: Medium
CVSS 9.8 Published: 2026-05-26
CWE-94

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

WAF Coverage Analysis

Code Injection Medium WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution 933xxx - PHP Injection 934xxx - Node.js / Generic Injection

Affected Software

VendorProductVersion
ibmwebsphere_application_server8.5.0.0 - 8.5.5.29
ibmwebsphere_application_server8.5.0.0 - 8.5.5.29
ibmwebsphere_application_server9.0.0.0 - 9.0.5.27
ibmwebsphere_application_server9.0.0.0 - 9.0.5.27

References

Back to CVE Database