CVE-2026-8400
EUVD-2026-5343805.08.2026, 16:17
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | - |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 9.0.0.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ibm | websphere | 8.5 | CNA |
| ibm | websphere | 9.0 | CNA |
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| java-1.8.0-ibm |
| ||
| java-1.8.0-ibm-demo |
| ||
| java-1.8.0-ibm-devel |
| ||
| java-1.8.0-ibm-headless |
| ||
| java-1.8.0-ibm-jdbc |
| ||
| java-1.8.0-ibm-plugin |
| ||
| java-1.8.0-ibm-src |
| ||
| java-1.8.0-ibm-webstart |
|