CVE-2026-9072
Undergoing Analysis Undergoing Analysis - In Progress
Remote Code Execution in IBM WebSphere WebServer Plug-in

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: IBM Corporation

Description
IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server *
ibm websphere_application_server_liberty *
ibm i *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects IBM i versions 7.3 through 7.6, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty when using Intelligent Management with the WebSphere WebServer Plug-in component.

An attacker can exploit this vulnerability by impersonating backend servers and sending specially crafted responses to the plug-in.

This exploitation can lead to remote code execution and denial of service on the affected systems.

Impact Analysis

The vulnerability can have severe impacts including allowing an attacker to remotely execute arbitrary code on the affected system.

It can also cause denial of service, potentially disrupting availability of services relying on the IBM WebSphere Application Server or IBM i systems.

Because the attack requires no privileges or user interaction, it poses a significant security risk.

Mitigation Strategies

To mitigate this vulnerability, IBM recommends applying the provided PTFs specific to your IBM i version: SJ10119 for 7.3, SJ10120 for 7.4, SJ10121 for 7.5, and SJ10122 for 7.6.

Currently, there are no available workarounds for this vulnerability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9072. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart