IBM Product Security Update Advisory
Overview
IBM has released security updates to address vulnerabilities in IBM WebSphere Application Server and WebSphere Application Server – Liberty. Users of these products should apply the latest version or the specified interim fix.
Affected Products and Vulnerabilities
- CVE-2026-14529: A server-side request forgery (SSRF) vulnerability affecting IBM WebSphere Application Server and WebSphere Application Server – Liberty.
- CVE-2026-15057: A denial-of-service (DoS) vulnerability in IBM WebSphere Application Server – Liberty caused by uncontrolled heap allocation.
Affected Versions and Fixed Versions
- CVE-2026-14529
- IBM WebSphere Application Server 8.5.0.0 Through 8.5.5.30
- IBM WebSphere Application Server 9.0.0.0 Through 9.0.5.28
- IBM WebSphere Application Server – Liberty 17.0.0.3 Through 26.0.0.8
- Fixed versions: IBM WebSphere Application Server 8.5.5.31 Or later, 9.0.5.29 Or later, IBM WebSphere Application Server – Liberty 26.0.0.9 Or later, or apply APAR DT495928 Interim Fix or APAR PH72053 Interim Fix
- CVE-2026-15057
- IBM WebSphere Application Server – Liberty 17.0.0.3 Or later through 26.0.0.7
- Resolved versions: IBM WebSphere Application Server – Liberty 26.0.0.8 Or later, or apply APAR PH72167 Interim Fix
Action Required
IBM recommends updating to the latest version with the Vulnerability Patch, as outlined in the reference site.