[UPDATE] [hoch] IBM WebSphere Application Server Liberty: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um seine Privilegien zu erhöhen.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities to perform denial of service, bypass security measures, and escalate privileges.
- Who is affected
- Any WebSphere Application Server Liberty deployment.
- Urgency
- High priority; multiple attack vectors including privilege escalation warrant immediate remediation.
- Action
- Apply IBM security patches for CVE-2026-10571, CVE-2026-14525, and CVE-2026-18499 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WebSphere Application Server Liberty
Get an email when a new WebSphere Application Server Liberty advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2807
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-105710.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-145250.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-184990.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10571 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14525 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18499 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis
- criticalCVE-2026-14525: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application…nvd
- mediumCVE-2026-10571: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial o…nvd
- unknownIBM WebSphere Products Multiple Vulnerabilitieshkcert
- highCVE-2026-18499: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privil…nvd
Recent advisories for IBM WebSphere Application
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] IBM WebSphere Application Server: Mehrere Schwachstellencert-bund · 2026-09-11
- mediumCVE-2026-9667: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSR…nvd · 2026-09-10
- mediumCVE-2026-9327: IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-priv…nvd · 2026-09-10
- mediumCVE-2026-9176: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to imprope…nvd · 2026-09-10
- mediumCVE-2026-9338: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by s…nvd · 2026-09-10
- mediumCVE-2026-9336: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by s…nvd · 2026-09-10
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14