CVE-2026-11595 – IBM WebSphere Application Server

CVSS 4.3 MODERATE Critical - Same Day Deployment

“Administrative tools deserve the same level of protection as the applications they manage.”

IBM has released security updates for WebSphere Application Server 9.0 and 8.5 to address multiple vulnerabilities affecting the administrative console and its integrated help system. CVE-2026-11712 and CVE-2026-11708 are cross-site scripting (XSS) vulnerabilities (CWE-79) that could allow malicious script execution within the administrative console. CVE-2026-11595 is an information disclosure vulnerability (CWE-22) that could allow a remote attacker to obtain sensitive information from the integrated help system.

CVE-2026-11712 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11708 has a CVSS score of 9.3, which is Critical severity. CVE-2026-11595 has a CVSS score of 4.3, which is Medium severity. Based on the information provided, there is no verified exploitation associated with these vulnerabilities. Organizations running affected WebSphere Application Server versions should apply the available updates to reduce the risk of administrative console compromise and information exposure.

Key Details

Affected Product
Ibm Websphere Application Server
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-22
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.