PatchSiren cyber security CVE debrief
CVE-2026-4410 IBM CVE debrief
IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, along with WebSphere Application Server 9.0 and 8.5, contain a denial-of-service vulnerability. A remote attacker can exploit this flaw by sending a specially crafted request, causing the server to consume excessive memory resources. The CVSS 3.1 vector (AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates this requires adjacent network access, high attack complexity, and low privileges, with no impact to confidentiality or integrity but high availability impact. IBM has published remediation guidance.
- Vendor
- IBM
- Product
- WebSphere Application Server - Liberty
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-01
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-01
Who should care
Organizations running IBM WebSphere Application Server Liberty versions 19.0.0.7 through 26.0.0.5, or WebSphere Application Server 9.0/8.5, particularly those with exposed management interfaces or limited network segmentation. Infrastructure teams responsible for Java application server security and availability should prioritize patching.
Technical summary
The vulnerability stems from improper handling of specially crafted requests leading to uncontrolled memory consumption (CWE-400). Affected components include IBM WebSphere Application Server Liberty (19.0.0.7-26.0.0.5), WebSphere Application Server 9.0, and 8.5. The attack requires adjacent network access and low privileges but high attack complexity, resulting in high availability impact through memory resource exhaustion. No confidentiality or integrity impacts are associated with this vulnerability.
Defensive priority
medium
Recommended defensive actions
- Apply IBM-provided security updates for affected WebSphere Application Server versions per vendor guidance
- Review network segmentation to limit adjacent network access to WebSphere management interfaces
- Monitor server memory utilization for anomalous consumption patterns
- Validate that WebSphere deployments run supported versions (Liberty 26.0.0.6 or later, or vendor-specified fixes)
- Assess exposure of WebSphere administrative interfaces and restrict access to authorized hosts only
Evidence notes
The vulnerability affects multiple IBM WebSphere Application Server versions including Liberty 19.0.0.7-26.0.0.5, WAS 9.0, and WAS 8.5. The attack vector requires adjacent network access with high complexity, limiting widespread exploitation. No evidence of known ransomware campaign use or CISA KEV inclusion as of the source publication date.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7273424
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.