critical
CVE-2026-14512
WebSphere pre-authentication unsafe deserialization -> auth bypass / RCE
- Severity
- critical
- Affected product
- IBM WebSphere Application Server
- Affected versions
- IBM WebSphere Application Server all versions before the fix
- Fixed in
- IBM WebSphere Application Server IBM interim fix (8.5 / 9.0)
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-07-29
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the IBM WebSphere Application Server appliance and reports this CVE when the detected version falls inside the affected range below.
Both CVEs affect ALL of 8.5 and 9.0 traditional, and IBM ships the fix as an interim fix (PH*) that does NOT change the reported version - so a version match cannot tell patched from unpatched. Deliberately NO `lt`: these stay an exposure advisory ("confirm the interim fix"), never a version-gated finding, or every patched 9.0 host would be a false positive. Not on CISA KEV as of the 2026-07-29 catalog (2026.07.27); EPSS from FIRST.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →