CVE-2026-14974

Summary

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

Affected Software

VendorProductVersion RangeStatus
IBMWebSphere Application Server8.5affected
IBMWebSphere Application Server9.0affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of Untrusted Data

References