logo

CVE-2026-11707: IBM WebSphere Application Server Admin Console XSS (CVSS 9.3)

ID: 2eaf3510-3762-57e9-ad08-ebd0f52790c0

STIX ID: report--2eaf3510-3762-57e9-ad08-ebd0f52790c0

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

...
...

IBM disclosed CVE-2026-11707, a critical (CVSS 3.1 9.3) XSS vulnerability in the WebSphere administrative console login page affecting WAS 8.5 and 9.0 (and bundled components), which allows unauthenticated attackers to inject JavaScript that can lead to session hijacking, credential theft, and full administrative compromise; IBM provides interim fixes and upcoming fix packs and recommends immediate patching and access restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.