nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8400 CVE-2026-8400
HIGH
Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
Record summary
CVE-2026-8400 has a selected CVSS score of 8.1 (high).
Description
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WebSphere Application ServerBrowse IBM / WebSphere Application Server | CVE List | 8.5 | affected |
| 9.0 | affected | ||
WebSphere Application Server - LibertyBrowse IBM / WebSphere Application Server - Liberty | CVE List | Continuous delivery | affected |
References
2ibm.comVendor advisorypatch
https://www.ibm.com/support/pages/node/7282446