{"id":"CVE-2026-2310","title":"IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data","summary":"IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-91"],"vendor":"IBM","product":"webMethods Integration Server","affected":["webmethods_integration_server 11.1"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T18:46:26.061541Z"},"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:31:09.333Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-2310","references":[{"url":"https://www.ibm.com/support/pages/node/7286620"}],"tags":["cve.org"],"epss":0.00265,"epssPercentile":0.18656,"ingestedAt":"2026-09-14T11:11:19.881Z","slug":"CVE-2026-2310","body":"## Overview\n\nIBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.\n\n## Affected\n\n- `webmethods_integration_server 11.1`\n\n## Remediation\n\nIBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document.\n\n\n\nIS_11.1_Core_Fix14 or later\n\n\n\nFixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491 )","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}