CVE-2026-8644Critical· 9.1▾ MidnightIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
websphere_application_server >= 8.5.0.0, < 8.5.5.30websphere_application_server >= 9.0.0.0, < 9.0.5.29Upgrade past the affected range:
websphere_application_server 9.0.5.29Connected by shared product, vendor, weakness, or advisory.
CVE-2026-18065Medium· 5.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.
CVE-2026-9176Medium· 6.7IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls
CVE-2026-9327Medium· 6.3IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration
CVE-2026-9336Medium· 6.5IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint
CVE-2026-9338Medium· 5.3IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request
CVE-2026-9667Medium· 5.3IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.