Security Advisory

IBM i and WebSphere Liberty: denial of service, HTTP request smuggling, and remote code execution

Critical Last verified

What Happened

IBM published a security bulletin covering five CVEs (CVE-2026-10852, CVE-2026-8858, CVE-2026-9072, CVE-2026-8633, CVE-2026-8620) affecting WebSphere Application Server Liberty as shipped on IBM i, spanning denial of service, HTTP request smuggling, and remote code execution risk.

Why It Matters

WebSphere Liberty underpins many IBM i web-facing applications and administrative interfaces (including Access Client Solutions and custom web apps). A remote code execution path on an internet-facing or lightly segmented Liberty instance is a serious exposure, not a theoretical one.

Recommended Actions

  • Identify every LPAR and instance running WebSphere Liberty on IBM i, including embedded/administrative uses
  • Match installed Liberty versions against IBM's affected-product table in the bulletin
  • Apply IBM's listed fix or documented mitigation on every affected instance
  • Re-verify externally-facing Liberty endpoints are not exposed beyond what business need requires

Sources