CVE-2026-11536
HIGHDescription
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Is your site exposed to CVE-2026-11536?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | websphere_application_server |
| ibm | websphere_application_server |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-11536? +
How severe is CVE-2026-11536? +
What products are affected by CVE-2026-11536? +
How do I check if I'm vulnerable to CVE-2026-11536? +
Related Vulnerabilities
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands …
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI …
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in …
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize …
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite …
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used …