CVE-2026-9072: IBM I
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in.
Affected products
- IBM I: from 7.3, up to and including 7.6
Published 2026-06-22. Last modified 2026-07-09.