Critical Vulnerabilities in IBM WebSphere Allow Remote Code Execution

Critical Vulnerabilities in IBM WebSphere Allow Remote Code Execution

First seen 3 Jun 2026, 12:55 UTC CybersecuritynewsHeise.DeIntegsecwww.ibm.com 91% similarity 72.6

Article Content

Browse articles
ThreatCluster

IBM has disclosed multiple critical vulnerabilities in its WebSphere Application Server, including CVE-2026-8633, which allows remote code execution via crafted HTTP requests. Other vulnerabilities, such as CVE-2026-9311, CVE-2026-9319, and CVE-2026-8644, enable attackers to bypass security controls and execute malicious code. The flaws primarily affect enterprise environments using WebSphere, raising significant risks for organizations reliant on these systems. Administrators are urged to apply security patches promptly, as there is no indication of active exploitation yet. IBM has also addressed vulnerabilities in its Business Automation Workflow, with CVE-2026-33186 allowing authentication bypass. The security updates are available in specific versions of the affected software. The situation remains critical as organizations work to secure their systems.

Key Points: • Multiple critical vulnerabilities in IBM WebSphere Application Server allow remote code execution. • CVE-2026-8633 enables arbitrary code execution through crafted HTTP requests. • Administrators must apply security patches immediately to mitigate risks.

ThreatCluster AI

Timeline

2026-03-20
CVE-2026-33186 published
A critical vulnerability in IBM Business Automation Workflow was disclosed, allowing authentication bypass.
Heise.De
2026-04-07
First public PoC for CVE-2026-33186
A proof of concept for the critical vulnerability in Business Automation Workflow was made public.
Heise.De
2026-05-26
CVE-2026-8633 published
IBM disclosed a critical vulnerability allowing remote code execution via crafted requests.
Cybersecuritynews
2026-06-01
CVE-2026-8644, 9311, and 9319 published
Three critical vulnerabilities were disclosed, enabling security control bypass and malicious code execution.
Heise.De
2026-06-01
CVE-2026-9330 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-01
CVE-2026-9311 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-01
CVE-2026-9319 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
Recent
Security patches released
IBM released security updates for affected versions of WebSphere and Business Automation Workflow.
Heise.De

Community

Browse all →