


Perceptive Security
SOC/SIEM Consultancy

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints wit…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 20:04:42
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
IBM WebSphere Application Server versions 9.0 and 8.5 contain a critical vulnerability that allows potential remote code execution. The flaw is caused by deserialization of untrusted data via JAX-WS endpoints with WS-Security. This vulnerability affects enterprise application servers and could allow attackers to execute arbitrary code remotely. The issue is related to unsafe deserialization practices in web service security implementations. Organizations using affected WebSphere versions should prioritize patching or implementing mitigations.
Technical details
Mitigation steps:
Affected products:
IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
