SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15396

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5, along with WebSphere Application Server - Liberty, are susceptible to HTTP request smuggling due to improper parsing of the HTTP transfer-encoding request header. This vulnerability allows attackers to potentially poison the web cache, bypass web application firewalls, and execute cross-site scripting (XSS) attacks. Organizations using these versions should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15396
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.