IBM Product Security Update Advisory

IBM Product Security Update Advisory
  • IBM has released security updates to address vulnerabilities in IBM products.
  • Affected versions include IBM WebSphere Application Server 8.5 Through 8.5.5.29, 9.0 Through 9.0.5.28, And IBM WebSphere Application Server – Liberty 17.0.0.3 Through 26.0.0.6.
  • The vulnerabilities addressed include CVE-2026-8646, an HTTP request smuggling vulnerability (exploiting HTTP request boundaries) in IBM WebSphere Application Server and IBM WebSphere Application Server – Liberty, as well as the denial-of-service (a condition that disrupts normal service usage) vulnerabilities CVE-2026-9071 and CVE-2026-9320.
  • IBM has provided patches through the latest updates; IBM WebSphere Application Server must be updated to version 8.5.5.30 Or higher, or 9.0.5.29 Or higher, and IBM WebSphere Application Server – Liberty must be updated to version 26.0.0.7 Or higher.
  • This procedure explains how to apply the latest version of the Vulnerability Patch according to the instructions on the reference site.