Security Advisory
IBM i and WebSphere Liberty: denial of service, HTTP request smuggling, and remote code execution
What Happened
IBM published a security bulletin covering five CVEs (CVE-2026-10852, CVE-2026-8858, CVE-2026-9072, CVE-2026-8633, CVE-2026-8620) affecting WebSphere Application Server Liberty as shipped on IBM i, spanning denial of service, HTTP request smuggling, and remote code execution risk.
Why It Matters
WebSphere Liberty underpins many IBM i web-facing applications and administrative interfaces (including Access Client Solutions and custom web apps). A remote code execution path on an internet-facing or lightly segmented Liberty instance is a serious exposure, not a theoretical one.
Recommended Actions
- Identify every LPAR and instance running WebSphere Liberty on IBM i, including embedded/administrative uses
- Match installed Liberty versions against IBM's affected-product table in the bulletin
- Apply IBM's listed fix or documented mitigation on every affected instance
- Re-verify externally-facing Liberty endpoints are not exposed beyond what business need requires
Sources
Other Tracked Advisories
- IBM i and OpenSSH: multiple vulnerabilities High severity
- IBM Power system update for a service processor vulnerability High severity
- IBM i and Java: multiple IBM Java SDK and Runtime vulnerabilities Medium severity