CVE-2026-5516: IBM WebSphere Application Server

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.

Affected products

  • IBM WebSphere Application Server: from 22.0.0.11, up to and including 26.0.0.5

Published 2026-05-27. Last modified 2026-06-17.