Threat reportVulnerabilityTL-2026-0650
IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)
IBM WebSphere Application Server & Liberty Web Server (TL-2026-0650) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects IBM WebSphere Application Server (traditional) - Web Server Plug-ins, references 2 CVEs (CVE-2026-8633, CVE-2026-8620), maps to 10 MITRE ATT&CK techniques (T1059, T1071, T1082), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-0650
- Threat ID
- TL-2026-0650
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- financial, government, healthcare, telecommunications, retail, insurance, manufacturing
- Target regions
- Global, North America, Europe, Asia Pacific
- Detection rules
- 9
- Indicators of compromise
- 14
How IBM WebSphere Application Server & Liberty Web Server works
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 contain a critical unauthenticated remote code execution flaw (CVE-2026-8633, CWE-94, CVSS 9.8) reachable via a specially crafted HTTP request, alongside a high-severity HTTP request smuggling flaw (CVE-2026-8620, CWE-444, CVSS 7.5) in the same native plug-in. Because the plug-in is a native module loaded directly into the front-end web server (IBM HTTP Server / Apache / IIS), successful exploitation yields code execution in the internet-facing web tier with no authentication or user interaction.
IBM disclosed two vulnerabilities on 26 May 2026 affecting the Web Server Plug-ins component shipped with IBM WebSphere Application Server (traditional) and WebSphere Application Server Liberty, versions 8.5 and 9.0 (IBM Security Bulletin, node 7274072; tracked under APAR PH71342).
The Web Server Plug-ins are not part of the application server JVM. They are native modules (for example was_ap24_module / mod_was_ap24_http.so for Apache 2.4-based IBM HTTP Server 9.0, was_ap22_module / mod_was_ap22_http.so for Apache 2.2, plus ISAPI/NSAPI variants) that are loaded via a LoadModule directive directly into the front-end web server worker process. The plug-in reads plugin-cfg.xml, parses inbound HTTP requests, applies routing/affinity rules, and forwards matched traffic to back-end WebSphere application servers over the WCInbound transport (HTTP or HTTPS, the latter secured with the bundled GSKit SSL library). Because the plug-in runs in-process inside the web server, any memory-safety or code-generation defect in its request-parsing path executes with the privileges of the web server process — typically a low-privileged service account (apache/nobody/www on Unix, the IHS service account on Windows), but on the internet-facing edge of the environment.
CVE-2026-8633 (CVSS 3.1 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) is classified CWE-94, Improper Control of Generation of Code (Code Injection). Per NVD and IBM, an unauthenticated remote attacker can trigger arbitrary code execution in the Web Server Plug-ins by sending a specially crafted request. The combination of network attack vector, low attack complexity, and no privileges or user interaction means a single crafted HTTP request to an exposed plug-in-fronted endpoint is sufficient to attempt code execution in the web tier — a direct pathway toward back-end WebSphere systems, internal network pivoting, and data on the application server.
CVE-2026-8620 (CVSS 3.1 7.5, vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N) is classified CWE-444, Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling), in the same plug-in. A discrepancy in how the plug-in parses request framing (for example, ambiguous or conflicting Content-Length and Transfer-Encoding handling) versus the front-end web server or the back-end WAS allows an attacker to desynchronize the request stream, smuggle a second request past front-end inspection, poison shared connections, and reach paths or controls that perimeter defenses (WAFs, access rules) believe are protected. The Scope:Changed metric reflects that the impact crosses the trust boundary between the front-end and back-end tiers.
Analyst assessment: the two flaws reside in the same request-processing component and are plausibly chainable — request smuggling (CVE-2026-8620) to bypass perimeter inspection or reach a restricted code path, combined with the code-injection primitive (CVE-2026-8633) to achieve execution. IBM's bulletin documents the two as distinct issues remediated together and does not assert an exploit chain; the chaining here is Threadlinqs analyst hypothesis based on component co-location and the typical smuggling-to-RCE pattern, not vendor-confirmed.
As of this analysis (1 June 2026) there is no public proof-of-concept exploit, no reported in-the-wild exploitation, and neither CVE appears in the CISA Known Exploited Vulnerabilities catalog. IBM published the bulletin and an interim fix (APAR PH71342) concurrently with disclosure; permanent Fix Packs (9.0.5.28+ for the 9.0 stream, 8.5.5.30+ for the 8.5 stream) are slated for upcoming release cycles. No indicators of compromise (C2 infrastructure, malware hashes, attacker domains) have been published by any source; this record therefore documents analyst-derived behavioral and host hunting indicators rather than fabricated network artifacts.
MITRE ATT&CK techniques used in TL-2026-0650
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Persistence
T1505 Server Software Component
Credential Access
Reconnaissance
Affected products and versions in IBM WebSphere Application Server & Liberty Web Server
- IBM — WebSphere Application Server (traditional) - Web Server Plug-ins
Vulnerable versions: 8.5.0.0 - 8.5.5.29; 9.0.0.0 - 9.0.5.27
Fixed in: 8.5.5.30 (when released); 9.0.5.28 (when released); interim fix APAR PH71342 - IBM — WebSphere Application Server Liberty - Web Server Plug-ins
Vulnerable versions: 8.5.0.0 - 8.5.5.29; 9.0.0.0 - 9.0.5.27
Fixed in: 8.5.5.30 (when released); 9.0.5.28 (when released); interim fix APAR PH71342
Remediation for IBM WebSphere Application Server & Liberty Web Server
Patches
- IBM interim fix for APAR PH71342 (available at disclosure).
- WebSphere Application Server 9.0: upgrade to Fix Pack 9.0.5.28 or later when released.
- WebSphere Application Server 8.5: upgrade to Fix Pack 8.5.5.30 or later when released.
Immediate actions
- Apply the IBM interim fix for APAR PH71342 to all WebSphere Application Server and Liberty 8.5/9.0 installations that have the Web Server Plug-ins deployed.
- Inventory all IBM HTTP Server / Apache / IIS front ends loading was_ap24_module, was_ap22_module, mod_was_ap24_http.so, mod_was_ap22_http.so, or the ISAPI/NSAPI plug-in and restrict their exposure to the public internet where possible.
- Deploy WAF / reverse-proxy rules to reject requests with ambiguous or conflicting Content-Length and Transfer-Encoding headers to mitigate the request-smuggling vector (CVE-2026-8620).
Workarounds
- No official IBM workaround other than the interim fix; compensating mitigations include front-end request normalization, removing/disabling unused plug-in modules, and restricting network exposure of plug-in-fronted endpoints.
Longer-term hardening
- Establish a patch-management cadence to move to permanent Fix Packs (9.0.5.28+, 8.5.5.30+) as soon as they are released.
- Segment the web-server/plug-in tier from back-end WebSphere application servers and internal networks to limit blast radius of web-tier code execution.
- Enforce HTTP request normalization at the front-most proxy so that one canonical interpretation of request framing is forwarded to the plug-in.
- Deploy EDR/host monitoring on web servers to alert on anomalous child processes spawned by the IBM HTTP Server / httpd worker.
CVEs associated with IBM WebSphere Application Server & Liberty Web Server
Weaknesses (CWE) in IBM WebSphere Application Server & Liberty Web Server
Timeline of IBM WebSphere Application Server & Liberty Web Server
- IBM makes the interim fix for APAR PH71342 available concurrently with disclosure; permanent Fix Packs (9.0.5.28, 8.5.5.30) scheduled for upcoming release cycles.
- CVE-2026-8633 (CWE-94 code injection, CVSS 9.8) and CVE-2026-8620 (CWE-444 HTTP request smuggling, CVSS 7.5) published to NVD.
- IBM publishes Security Bulletin (node 7274072) disclosing CVE-2026-8633 and CVE-2026-8620 in WebSphere Application Server and Liberty Web Server Plug-ins; tracked under APAR PH71342.
- NVD last-modified date for CVE-2026-8633; independent security press (CybersecurityNews, SecurityOnline, HKCERT, ASEC, UCLA OCISO) republish advisory coverage.
- Threadlinqs Intelligence publishes full threat analysis with MITRE ATT&CK mapping, plug-in component analysis, and analyst-derived hunting indicators.
- Threadlinqs review confirms neither CVE-2026-8633 nor CVE-2026-8620 is listed in the CISA Known Exploited Vulnerabilities catalog; no public PoC or in-the-wild exploitation identified.
Sources cited for IBM WebSphere Application Server & Liberty Web Server
- NVD - CVE-2026-8633 Detail
- NVD - CVE-2026-8620 Detail
- IBM Security Bulletin: WebSphere Application Server and Liberty affected by multiple vulnerabilities when using Web Server Plug-ins (CVE-2026-8633, CVE-2026-8620)
- IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request
- WebSphere Remote Code Execution Defended with New IBM Security Fixes
- IBM WebSphere Application Server Remote Code Execution Vulnerability
- IBM Product Security Update Advisory - ASEC
- A Vulnerability in IBM WebSphere Application Server Could Allow for Remote Code Execution - UCLA OCISO
Detection coverage for TL-2026-0650
As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0650 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.