Critical XSS and Path Traversal Vulnerabilities in IBM WebSphere Application Server
Article Content
- •IBM disclosed critical XSS and path traversal vulnerabilities in WebSphere Application Server.
- •Affected versions include widely deployed 8.5 and 9.0, with CVEs published on June 30, 2026.
- •Attackers could exploit these vulnerabilities to access sensitive data and compromise admin sessions.
IBM has disclosed critical vulnerabilities in its WebSphere Application Server, specifically CVE-2026-11712, CVE-2026-11595, and CVE-2026-11708, which affect widely used versions 8.5 and 9.0. These vulnerabilities enable cross-site scripting (XSS) and path traversal attacks, potentially allowing attackers to compromise administrative sessions and access sensitive data. The issues were published on June 30, 2026, and pose significant risks to enterprises relying on this platform for critical operations. Organizations are urged to assess their systems for these vulnerabilities and apply necessary mitigations. The vulnerabilities have been confirmed by IBM and are a serious concern for affected users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-11595 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…