CVE-2026-10852: medium-severity vulnerability in IBM WebSphere Application Server
Websphere Application Server is Affected By a Denial of Service
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
IBM · WebSphere Application ServerRelated CVEs — IBM WebSphere Application Server
In the same product, most dangerous first.