CVE-2026-13759: IBM WebSphere Extreme Scale
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs
Affected products
- IBM WebSphere Extreme Scale: from 8.6.1.0, up to and including 8.6.1.6
Published 2026-06-30. Last modified 2026-07-03.