PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10842 IBM CVE debrief

IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 are affected by a high-severity vulnerability allowing remote attackers to bypass security constraints. The vulnerability has a CVSS score of 7.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Organizations should review and apply patches or updates provided by IBM to address the vulnerability. Affected product deployments should be identified, and security configurations should be reviewed and updated. Monitoring for potential exploitation attempts is also recommended.

Vendor
IBM
Product
WebSphere Application Server
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-08-05
Advisory published
2026-07-30
Advisory updated
2026-08-05

Who should care

Organizations using IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 should be aware of this high-severity vulnerability and take steps to mitigate it. Operators, platform administrators, vulnerability management teams, and security teams should review and apply patches or updates provided by IBM to address the vulnerability.

Technical summary

IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 could allow a remote attacker to bypass security constraints due to improper security configuration. The vulnerability has a CVSS score of 7.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Affected organizations should prioritize patching due to the high CVSS score.

Defensive priority

Organizations using IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 should prioritize patching due to the high CVSS score of 7.5.

Recommended defensive actions

  • Apply patches or updates provided by IBM to address the vulnerability
  • Review and update security configurations for IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record indicates that IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 could allow a remote attacker to bypass security constraints. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a high severity vulnerability. Evidence is limited to CVE and NVD details. Defenders should verify affected scope and apply patches or updates provided by IBM.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T16:16:53.980Z and has not been modified since then.