CVE-2026-9176

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.

  • Published Sep 10, 2026
  • CVSS 7.1 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-9176 at the National Vulnerability Database