CVE-2026-13773: IBM WebSphere Extreme Scale
Critical severity, CVSS 10.0. EPSS: 6.1% chance of exploitation in the next 30 days.
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.
Affected products
- IBM WebSphere Extreme Scale: from 8.6.1.0, up to and including 8.6.1.6
Published 2026-06-30. Last modified 2026-07-02.