<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WebSphere Application Server - Liberty (Continuous Delivery) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/websphere-application-server---liberty-continuous-delivery/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 05 Aug 2026 17:20:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/websphere-application-server---liberty-continuous-delivery/feed.xml" rel="self" type="application/rss+xml"/><item><title>IBM WebSphere Application Server ORB Unsafe Reflection Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-ibm-websphere-orb-rce/</link><pubDate>Wed, 05 Aug 2026 17:20:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ibm-websphere-orb-rce/</guid><description>A vulnerability in the Object Request Broker (ORB) component of IBM SDK for Java allows an unauthenticated attacker to trigger remote code execution via arbitrary class instantiation.</description><content:encoded><![CDATA[<p>IBM WebSphere Application Server versions 8.5, 9.0, and the Liberty Continuous Delivery release contain a critical vulnerability in the Object Request Broker (ORB) component of the integrated IBM SDK, Java Technology Edition. Tracked as CVE-2026-8400, the flaw is classified under CWE-470 (Use of Externally-Controlled Input to Select Classes or Code). This vulnerability stems from unsafe reflection practices within the ORB's handling of IIOP (Internet Inter-ORB Protocol) traffic. An attacker operating a malicious IIOP server can send specially crafted requests to a vulnerable WebSphere instance, inducing the application to load and instantiate arbitrary classes. This primitive effectively allows for remote code execution, as the attacker can manipulate the application environment to execute arbitrary code or bypass security controls. Defenders should prioritize patching, as this vulnerability carries a CVSS 3.1 base score of 8.1.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthenticated remote code execution on affected WebSphere Application Server instances. This impact potentially grants an attacker full control over the application server process, enabling data exfiltration, service disruption, or further lateral movement within the network. This affects enterprise organizations utilizing IBM WebSphere for critical Java-based business applications.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the application of official security patches from IBM for WebSphere Application Server and the associated IBM SDK for Java Technology Edition. Consult the IBM security bulletin at <a href="https://www.ibm.com/support/pages/node/7282446">https://www.ibm.com/support/pages/node/7282446</a> for specific fix levels. As an immediate measure, restrict network access to the IIOP port (typically 2809) to trusted management segments only.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>java</category></item></channel></rss>