


Perceptive Security
SOC/SIEM Consultancy

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side …
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 20:03:55
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
IBM WebSphere Application Server versions 9.0 and 8.5, as well as IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8, are affected by a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability is triggered when the SIP container feature (sipServlet-1.1) is enabled. SSRF vulnerabilities can allow attackers to induce the server-side application to make HTTP requests to an arbitrary domain, potentially bypassing firewalls and accessing internal services. The vulnerability has been assigned CVE-2026-14529 and is catalogued in the NVD. IBM has published a support advisory with remediation guidance. Affected organizations should review whether the sipServlet-1.1 feature is enabled and apply patches or mitigations promptly. The high criticality rating reflects the potential for significant impact in enterprise environments running WebSphere.
Technical details
Mitigation steps:
Affected products:
IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.8
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
