IBM WebSphere Products Hit with Multiple Vulnerabilities, Patches Available
IBM WebSphere Products have been found to be vulnerable to multiple attacks. According to the Hong Kong Computer Emergency Response Team Coordination Centre, a remote attacker could exploit these vulnerabilities to trigger denial of service, elevation of privilege, and security restriction bypass on the targeted system.
The affected products include IBM WebSphere Application Server - Liberty version 17.0.0.3 to 26.0.0.8. Before installation, users are advised to visit the vendor's website for more information. To mitigate the risks, apply fixes issued by the vendor at https://www.ibm.com/support/pages/node/7283485, https://www.ibm.com/support/pages/node/7283488, and https://www.ibm.com/support/pages/node/7283489.
The vulnerabilities have been assigned the identifiers CVE-2026-10571, CVE-2026-14525, and CVE-2026-18499. IBM has provided patches to address these issues.