CVE-2025-14923: IBM WebSphere Application Server

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

Affected products

  • IBM WebSphere Application Server: from 17.0.0.3, before 26.0.0.3 (fixed in 26.0.0.3)

Published 2026-03-03. Last modified 2026-06-17.