CVE-2026-9319
Critical · CVSS 9.0- CVSS
- 9.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-502
Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
References
Status: profiled · ingested 2026-07-22T12:00:18.000Z