CVE-2025-14914: IBM WebSphere Application Server

High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

Affected products

  • IBM WebSphere Application Server: from 17.0.0.3, up to and including 26.0.0.1

Published 2026-02-02. Last modified 2026-06-17.