VYPR
advisoryPublished Sep 18, 2026· Updated Sep 21, 2026· 1 source

IBM WebSphere: Eleven Vulnerabilities Disclosed Together, Including HTTP Smuggling

Key findings • Eleven vulnerabilities disclosed together for IBM WebSphere Application Server and Liberty on September 18, 2026. • Multiple HTTP request smuggling flaws identified across diff…

Key findings

  • Eleven vulnerabilities disclosed together for IBM WebSphere Application Server and Liberty on September 18, 2026.
  • Multiple HTTP request smuggling flaws identified across different versions and profiles.
  • Vulnerabilities include deserialization, virtual host bypass, authentication bypass, and information disclosure.
  • Severity ranges from Low (CVSS 3.7) to Medium (CVSS 6.5).
  • Users urged to consult IBM advisories for patching and mitigation.

On September 18, 2026, a batch of eleven vulnerabilities was disclosed for IBM WebSphere Application Server and its Liberty profile. These vulnerabilities, disclosed within a four-hour window, span several bug classes including HTTP request smuggling, deserialization flaws, virtual host bypass, information disclosure, authentication bypass, and log injection. The clustered disclosure suggests a coordinated release of security information impacting various versions of the application server.

Several vulnerabilities revolve around HTTP request smuggling. CVE-2026-11722, CVE-2026-11548, and CVE-2026-10841 specifically mention this issue affecting WebSphere Application Server and Liberty. CVE-2026-11710 further details an HTTP request smuggling vulnerability in WebSphere Application Server 8.5, stemming from improper handling of Content-Length headers.

Other notable vulnerabilities include a deserialization flaw in the Name Service component affecting WebSphere Application Server 9.0 and 8.5 (CVE-2026-11711). A virtual host bypass vulnerability impacts both WebSphere Application Server and its Liberty profile (CVE-2026-11549). Information disclosure is also a theme, with CVE-2026-11540 and CVE-2026-11537 detailing how attackers could obtain sensitive file system information via the FileTransfer servlet in versions 9.0 and 8.5. Additionally, CVE-2026-11545 points to missing authorization checks in the administrative console that could lead to sensitive information disclosure, while CVE-2026-11538 describes an authentication bypass in the SOAP/JMX connector for versions 9.0 and 8.5. Lastly, CVE-2026-11538 highlights a log injection vulnerability through crafted LTPA token cookies in versions 9.0 and 8.5.

The disclosed vulnerabilities range in severity from Low (CVSSv3 3.7) to Medium (CVSSv3 6.5). While no specific threat actor or in-the-wild exploitation was mentioned in the disclosures, the breadth of issues indicates a significant security posture concern for users of IBM WebSphere Application Server.

IBM has provided advisories for these vulnerabilities, and users are urged to consult the official IBM security bulletins for specific remediation steps and affected version details. Prompt patching and applying vendor-recommended mitigations are crucial to protect against potential exploitation.

This batch of vulnerabilities underscores the importance of maintaining up-to-date security configurations for IBM WebSphere Application Server environments. Users should prioritize addressing these issues to prevent unauthorized access, information disclosure, and potential system compromise. Regular review of security advisories from IBM is recommended to stay informed about emerging threats and patches.

Synthesized by Vypr AI
IBM WebSphere: Eleven Vulnerabilities Disclosed Together, Including HTTP Smuggling · VYPR