Threat reportVulnerabilityTL-2026-0650

IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)

criticalMONITORING

IBM WebSphere Application Server & Liberty Web Server (TL-2026-0650) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects IBM WebSphere Application Server (traditional) - Web Server Plug-ins, references 2 CVEs (CVE-2026-8633, CVE-2026-8620), maps to 10 MITRE ATT&CK techniques (T1059, T1071, T1082), and is covered by 9 detection rules and 14 indicators of compromise.

CVSS
9.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-0650

Threat ID
TL-2026-0650
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
financial, government, healthcare, telecommunications, retail, insurance, manufacturing
Target regions
Global, North America, Europe, Asia Pacific
Detection rules
9
Indicators of compromise
14

How IBM WebSphere Application Server & Liberty Web Server works

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 contain a critical unauthenticated remote code execution flaw (CVE-2026-8633, CWE-94, CVSS 9.8) reachable via a specially crafted HTTP request, alongside a high-severity HTTP request smuggling flaw (CVE-2026-8620, CWE-444, CVSS 7.5) in the same native plug-in. Because the plug-in is a native module loaded directly into the front-end web server (IBM HTTP Server / Apache / IIS), successful exploitation yields code execution in the internet-facing web tier with no authentication or user interaction.

IBM disclosed two vulnerabilities on 26 May 2026 affecting the Web Server Plug-ins component shipped with IBM WebSphere Application Server (traditional) and WebSphere Application Server Liberty, versions 8.5 and 9.0 (IBM Security Bulletin, node 7274072; tracked under APAR PH71342).

The Web Server Plug-ins are not part of the application server JVM. They are native modules (for example was_ap24_module / mod_was_ap24_http.so for Apache 2.4-based IBM HTTP Server 9.0, was_ap22_module / mod_was_ap22_http.so for Apache 2.2, plus ISAPI/NSAPI variants) that are loaded via a LoadModule directive directly into the front-end web server worker process. The plug-in reads plugin-cfg.xml, parses inbound HTTP requests, applies routing/affinity rules, and forwards matched traffic to back-end WebSphere application servers over the WCInbound transport (HTTP or HTTPS, the latter secured with the bundled GSKit SSL library). Because the plug-in runs in-process inside the web server, any memory-safety or code-generation defect in its request-parsing path executes with the privileges of the web server process — typically a low-privileged service account (apache/nobody/www on Unix, the IHS service account on Windows), but on the internet-facing edge of the environment.

CVE-2026-8633 (CVSS 3.1 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) is classified CWE-94, Improper Control of Generation of Code (Code Injection). Per NVD and IBM, an unauthenticated remote attacker can trigger arbitrary code execution in the Web Server Plug-ins by sending a specially crafted request. The combination of network attack vector, low attack complexity, and no privileges or user interaction means a single crafted HTTP request to an exposed plug-in-fronted endpoint is sufficient to attempt code execution in the web tier — a direct pathway toward back-end WebSphere systems, internal network pivoting, and data on the application server.

CVE-2026-8620 (CVSS 3.1 7.5, vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N) is classified CWE-444, Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling), in the same plug-in. A discrepancy in how the plug-in parses request framing (for example, ambiguous or conflicting Content-Length and Transfer-Encoding handling) versus the front-end web server or the back-end WAS allows an attacker to desynchronize the request stream, smuggle a second request past front-end inspection, poison shared connections, and reach paths or controls that perimeter defenses (WAFs, access rules) believe are protected. The Scope:Changed metric reflects that the impact crosses the trust boundary between the front-end and back-end tiers.

Analyst assessment: the two flaws reside in the same request-processing component and are plausibly chainable — request smuggling (CVE-2026-8620) to bypass perimeter inspection or reach a restricted code path, combined with the code-injection primitive (CVE-2026-8633) to achieve execution. IBM's bulletin documents the two as distinct issues remediated together and does not assert an exploit chain; the chaining here is Threadlinqs analyst hypothesis based on component co-location and the typical smuggling-to-RCE pattern, not vendor-confirmed.

As of this analysis (1 June 2026) there is no public proof-of-concept exploit, no reported in-the-wild exploitation, and neither CVE appears in the CISA Known Exploited Vulnerabilities catalog. IBM published the bulletin and an interim fix (APAR PH71342) concurrently with disclosure; permanent Fix Packs (9.0.5.28+ for the 9.0 stream, 8.5.5.30+ for the 8.5 stream) are slated for upcoming release cycles. No indicators of compromise (C2 infrastructure, malware hashes, attacker domains) have been published by any source; this record therefore documents analyst-derived behavioral and host hunting indicators rather than fabricated network artifacts.

MITRE ATT&CK techniques used in TL-2026-0650

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Persistence

T1505 Server Software Component

Credential Access

T1552 Unsecured Credentials

Reconnaissance

T1595 Active Scanning

Affected products and versions in IBM WebSphere Application Server & Liberty Web Server

  • IBM — WebSphere Application Server (traditional) - Web Server Plug-ins
    Vulnerable versions: 8.5.0.0 - 8.5.5.29; 9.0.0.0 - 9.0.5.27
    Fixed in: 8.5.5.30 (when released); 9.0.5.28 (when released); interim fix APAR PH71342
  • IBM — WebSphere Application Server Liberty - Web Server Plug-ins
    Vulnerable versions: 8.5.0.0 - 8.5.5.29; 9.0.0.0 - 9.0.5.27
    Fixed in: 8.5.5.30 (when released); 9.0.5.28 (when released); interim fix APAR PH71342

Remediation for IBM WebSphere Application Server & Liberty Web Server

Patches

  • IBM interim fix for APAR PH71342 (available at disclosure).
  • WebSphere Application Server 9.0: upgrade to Fix Pack 9.0.5.28 or later when released.
  • WebSphere Application Server 8.5: upgrade to Fix Pack 8.5.5.30 or later when released.

Immediate actions

  • Apply the IBM interim fix for APAR PH71342 to all WebSphere Application Server and Liberty 8.5/9.0 installations that have the Web Server Plug-ins deployed.
  • Inventory all IBM HTTP Server / Apache / IIS front ends loading was_ap24_module, was_ap22_module, mod_was_ap24_http.so, mod_was_ap22_http.so, or the ISAPI/NSAPI plug-in and restrict their exposure to the public internet where possible.
  • Deploy WAF / reverse-proxy rules to reject requests with ambiguous or conflicting Content-Length and Transfer-Encoding headers to mitigate the request-smuggling vector (CVE-2026-8620).

Workarounds

  • No official IBM workaround other than the interim fix; compensating mitigations include front-end request normalization, removing/disabling unused plug-in modules, and restricting network exposure of plug-in-fronted endpoints.

Longer-term hardening

  • Establish a patch-management cadence to move to permanent Fix Packs (9.0.5.28+, 8.5.5.30+) as soon as they are released.
  • Segment the web-server/plug-in tier from back-end WebSphere application servers and internal networks to limit blast radius of web-tier code execution.
  • Enforce HTTP request normalization at the front-most proxy so that one canonical interpretation of request framing is forwarded to the plug-in.
  • Deploy EDR/host monitoring on web servers to alert on anomalous child processes spawned by the IBM HTTP Server / httpd worker.

CVEs associated with IBM WebSphere Application Server & Liberty Web Server

CVE-2026-8633, CVE-2026-8620

Weaknesses (CWE) in IBM WebSphere Application Server & Liberty Web Server

CWE-94, CWE-444

Timeline of IBM WebSphere Application Server & Liberty Web Server

  • IBM makes the interim fix for APAR PH71342 available concurrently with disclosure; permanent Fix Packs (9.0.5.28, 8.5.5.30) scheduled for upcoming release cycles.
  • CVE-2026-8633 (CWE-94 code injection, CVSS 9.8) and CVE-2026-8620 (CWE-444 HTTP request smuggling, CVSS 7.5) published to NVD.
  • IBM publishes Security Bulletin (node 7274072) disclosing CVE-2026-8633 and CVE-2026-8620 in WebSphere Application Server and Liberty Web Server Plug-ins; tracked under APAR PH71342.
  • NVD last-modified date for CVE-2026-8633; independent security press (CybersecurityNews, SecurityOnline, HKCERT, ASEC, UCLA OCISO) republish advisory coverage.
  • Threadlinqs Intelligence publishes full threat analysis with MITRE ATT&CK mapping, plug-in component analysis, and analyst-derived hunting indicators.
  • Threadlinqs review confirms neither CVE-2026-8633 nor CVE-2026-8620 is listed in the CISA Known Exploited Vulnerabilities catalog; no public PoC or in-the-wild exploitation identified.

Sources cited for IBM WebSphere Application Server & Liberty Web Server

Detection coverage for TL-2026-0650

As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0650 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats