Product
high
advisory
IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)
1 CVEA path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.
WebSphere Application Server - Liberty 17.0.0.3 +45
vulnerability
path-segment-injection
information-disclosure
websphere
ibm
1c
critical
advisory
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
WebSphere Application Server 9.0 +8
vulnerability
authentication-bypass
websphere
broken-access-control
privilege-escalation
deserialization
RCE
server-side-request-forgery
+6
5t
7c
5i