← All CVEs NewScan detects
critical

CVE-2026-14446

WebSphere admin-console broken access control -> privilege escalation

Severity
critical
Affected product
IBM WebSphere Application Server
Affected versions
IBM WebSphere Application Server all versions before the fix
Fixed in
IBM WebSphere Application Server IBM interim fix (8.5 / 9.0)
EPSS
0% chance of exploitation in the next 30 days
Added to NewScan
2026-07-29
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the IBM WebSphere Application Server appliance and reports this CVE when the detected version falls inside the affected range below.

Both CVEs affect ALL of 8.5 and 9.0 traditional, and IBM ships the fix as an interim fix (PH*) that does NOT change the reported version - so a version match cannot tell patched from unpatched. Deliberately NO `lt`: these stay an exposure advisory ("confirm the interim fix"), never a version-gated finding, or every patched 9.0 host would be a false positive. Not on CISA KEV as of the 2026-07-29 catalog (2026.07.27); EPSS from FIRST.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →