← back
CVE-2026-10852

Websphere Application Server is Affected By a Denial of Service in IBM WebSphere Application Server Liberty

CVSS 5.9 MEDIUMEPSS 0.3%CWE-476
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
22 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
IBM · i