SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14529

CRITICAL · CVSS 9.4 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5, along with Liberty versions 17.0.0.3 through 26.0.0.8, are susceptible to a critical server-side request forgery (SSRF) vulnerability when the SIP container feature is enabled. This flaw could allow an attacker to manipulate server requests, potentially leading to unauthorized access to internal resources. Organizations using these versions of WebSphere should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-14529
Severity
CRITICAL
CVSS
9.4
EPSS
0.40%

Original NVD Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Related CVEs

Other vulnerabilities affecting the same vendor(s)