Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3038 articles · 183963 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-14512PATCHED
ibm · websphere application server

IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information

Description

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

Affected Products

VendorProductVersions
ibmwebsphere application server9.0, 8.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmwebsphere application server libertycert_advisory90%
ibmwebsphere applicationcert_advisory90%

References

  • https://www.ibm.com/support/pages/node/7281649(vendor-advisory, patch)

Related News (4 articles)

Tier B
CERT-FR5d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier D
Heise Security6d ago
IBM WebSphere Application Server: Sicherheitsproblem in Admin-Konsole gelöst
→ No new info (linked only)
Tier B
BSI Advisories7d ago
[NEU] [hoch] IBM WebSphere Application Server und Application Server Liberty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-14512 | IBM WebSphere Application Server 8.5/9.0 deserialization
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ibm.com/support/pages/node/7281649
CWECWE-502
PublishedJul 28, 2026
Trending Score35
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-9198EXPKEV
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
Trending: 147
CRITICALCVE-2026-14446
IBM WebSphere Application Server is affected by a privilege escalation
Trending: 35
CRITICALCVE-2026-14529
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery
Trending: 33
CRITICALCVE-2026-15435
IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability
Trending: 32
HIGHCVE-2026-15280
IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 30, 2026