IBM has disclosed a critical remote code execution vulnerability affecting environments that use Web Server Plug-ins with IBM WebSphere Application Server and WebSphere Liberty. The flaw, tracked as CVE-2026-8633, could allow remote attackers to execute arbitrary code on vulnerable systems by sending specially crafted HTTP requests. The vulnerability has received a CVSS score of 9.8, highlighting its critical severity and the significant risk it poses to enterprise environments. According to IBM, the issue originates from improper control of code generation, classified under CWE-94. By exploiting this weakness, attackers can inject malicious payloads through crafted HTTP requests processed by vulnerable Web Server Plug-ins. Successful exploitation could result in unauthorized code execution, enabling attackers to gain extensive control over affected systems. The flaw may also facilitate HTTP request smuggling attacks, allowing malicious actors to bypass security controls and manipulate communications between web servers and backend applications. The vulnerability affects Web Server Plug-ins used with WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0. Because these plug-ins play a critical role in routing requests between web servers and application servers, exploitation could provide attackers with a direct path into sensitive enterprise infrastructure. The issue impacts confidentiality, integrity, and availability, potentially leading to complete system compromise. IBM has released remediation guidance and strongly advises organizations to apply the recommended fixes and updates as soon as possible. Security teams should also monitor HTTP traffic for suspicious activity, restrict unnecessary internet exposure of WebSphere services, implement web application firewall protections, and conduct threat-hunting activities to identify indicators of compromise. Timely patching and layered security controls are essential to mitigating the risks associated with this critical vulnerability.
Researchers have uncovered a targeted cyber espionage campaign, dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned threat group SideCopy. The operation primarily targe...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-21182, a critical vulnerability affecting Oracle WebLogic Server, to its Known Exploited Vulnera...
Dashlane has revealed that it recently detected and mitigated a targeted brute-force attack aimed at a limited number of user accounts. The incident triggered the company's aut...