CVE-2026-11536
Awaiting Analysis Awaiting Analysis - Queue

Remote Code Execution in IBM WebSphere Application Server

Vulnerability report for CVE-2026-11536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-31

Assigner: IBM Corporation

Description

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server 9.0
ibm websphere_application_server 8.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM WebSphere Application Server 9.0 and 8.5 has a remote code execution vulnerability in the SOAP/JMX connector. This allows an attacker to execute arbitrary code on the affected system remotely.

Detection Guidance

Detecting this vulnerability requires checking for IBM WebSphere Application Server versions 9.0 or 8.5 with exposed SOAP/JMX connectors. Inspect running services and open ports (typically 8880, 9402, 9633) using commands like netstat -tuln or ss -tuln. Verify server versions via IBM WebSphere administrative console or command-line tools like versionInfo.sh.

Impact Analysis

This vulnerability can lead to unauthorized remote access, data breaches, system compromise, and potential full control over the affected WebSphere server. Attackers could steal sensitive data or disrupt services.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations due to unauthorized data access or exposure. Organizations may face legal penalties and reputational damage if exploited.

Mitigation Strategies

Disable the SOAP/JMX connector if not required. Apply the latest IBM WebSphere Application Server patches immediately. Restrict network access to the SOAP/JMX ports. Monitor for unusual activity or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart