CVE-2026-2310: IBM Webmethods Integration Server

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Affected products

  • IBM Webmethods Integration Server: version 11.1 only

Published 2026-09-10. Last modified 2026-09-11.