CVE-2026-8400

EUVD-2026-53438
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Unsafe Reflection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ibmCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19.99%
Affected Products (NVD)
VendorProductVersion
ibmwebsphere_application_server
-
ibmwebsphere_application_server
8.5.0.0
ibmwebsphere_application_server
9.0.0.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ibmwebsphere
8.5
CNA
ibmwebsphere
9.0
CNA
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.8.0-ibm
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-demo
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-devel
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-headless
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-jdbc
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-plugin
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-src
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed
java-1.8.0-ibm-webstart
RHEL 8
1:1.8.0.8.70-1.el8_10
fixed