CVE-2025-36072: IBM Webmethods Integration

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.

Affected products

  • IBM Webmethods Integration: version 10.11 only; version 10.15 only; version 11.1 only

Published 2025-11-20. Last modified 2026-06-17.