top of page
perceptive_background_267k.jpg

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypa…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 22:02:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies, Zero-Day Vulnerabilities

IBM WebSphere Application Server versions 9.0 and 8.5 traditional are affected by a critical pre-authentication unsafe deserialization vulnerability. The flaw allows remote attackers to bypass authentication or execute arbitrary code without prior credentials. This makes it particularly dangerous as no user interaction or authentication is required to exploit it. The vulnerability impacts widely deployed enterprise Java application server software. IBM has published a support advisory with remediation guidance. The issue is tracked as CVE-2026-14512 and has been assigned a high criticality rating. Organizations running affected versions should apply patches immediately to reduce exposure risk.

Technical details

Mitigation steps:

Affected products:

IBM WebSphere Application Server 9.0
IBM WebSphere Application Server 8.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page