{"id":2730,"date":"2026-07-29T07:03:45","date_gmt":"2026-07-29T14:03:45","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=2730"},"modified":"2026-07-29T07:03:46","modified_gmt":"2026-07-29T14:03:46","slug":"emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/","title":{"rendered":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What are CVE-2026-14512 and CVE-2026-14446?<\/h2>\n\n\n\n<p>On July 28, 2026, IBM published two separate security bulletins covering critical vulnerabilities in WebSphere Application Server traditional. CVE-2026-14512 is a pre-authentication unsafe deserialization flaw, classified as deserialization of untrusted data (CWE-502), that allows a remote attacker to bypass authentication or execute arbitrary code. CVE-2026-14446 is a broken access control and privilege escalation flaw in the administrative console, classified as missing authentication for a critical function (CWE-306).<\/p>\n\n\n\n<p>Both vulnerabilities carry a CVSS v3.1 base score of 9.8 (Critical). Both are reachable over the network, and neither requires privileges or user interaction to exploit.<\/p>\n\n\n\n<p>Neither flaw requires an attacker to hold valid credentials. For CVE-2026-14512, successful exploitation means code execution in the context of the application server process, which typically holds access to application data, connection credentials, and the back-end systems the server integrates with. For CVE-2026-14446, the target is the control plane itself: the administrative console is where applications are deployed and where server and security configuration is changed, so unauthorized privileged access to it is equivalent to control of the server.<\/p>\n\n\n\n<p>IBM lists no workarounds or mitigations for either vulnerability. The bulletin covering CVE-2026-14512 also addresses CVE-2026-14528, a lower-severity flaw in which sensitive information is written into log files, scored 7.4. IBM has not published details of the affected protocol or endpoint for the deserialization flaw, and no public exploit code or in-the-wild exploitation had been reported at the time of writing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What assets are affected by CVE-2026-14512 and CVE-2026-14446?<\/h2>\n\n\n\n<p>Both vulnerabilities affect WebSphere Application Server traditional, versions 9.0.0.0 through 9.0.5.28 and 8.5.0.0 through 8.5.5.30. IBM lists both across the Advanced, Base, Developer, Enterprise, Express, Network Deployment, and Single Server editions, on AIX, IBM i, Linux, Windows, and z\/OS. WebSphere Application Server Liberty is not listed as affected by either flaw.<\/p>\n\n\n\n<p>In practice, an affected asset is a long-running Java EE application server sitting behind a web tier, frequently fronted by IBM HTTP Server and the WebSphere plug-in, and serving customer portals, order management, claims processing, payments, or similar core business functions. The administrative console is a separate surface on the same host, defaulting to <code>TCP\/9060<\/code> for HTTP and <code>TCP\/9043<\/code> for HTTPS at the <code>\/ibm\/console<\/code> path.<\/p>\n\n\n\n<p>These assets tend to be overlooked for structural reasons rather than careless ones. WebSphere deployments often predate the inventory systems meant to track them, and their hostnames rarely identify the platform underneath. Management interfaces intended for internal use become externally reachable through load balancer rules, legacy NAT configurations, or lift-and-shift cloud migrations that carry the original network exposure forward. Version upgrades are gated by application certification cycles, which is why estates sit on older fix pack levels long after a fix ships.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are fixes available?<\/h2>\n\n\n\n<p>Fixes are available. IBM has released interim fixes for both vulnerabilities, addressed by different APARs: PH72166 for CVE-2026-14512 and DT496500 for CVE-2026-14446. Because the two flaws are tracked separately, applying one does not remediate the other.<\/p>\n\n\n\n<p>For both version families, IBM&#8217;s guidance is to upgrade to the minimum fix pack level the interim fix requires and then apply the interim fix, or alternatively to move to Fix Pack 9.0.5.29 for the 9.0 line or Fix Pack 8.5.5.31 for the 8.5 line. Those fix packs carry a targeted availability of 3Q2026, which means the interim fix route is the only path to remediation at the time of writing. IBM lists no workarounds for either vulnerability, so there is no configuration change that substitutes for the fix.<\/p>\n\n\n\n<p>Organizations should confirm the current fix pack and interim fix availability directly with IBM for their specific version, platform, and edition rather than assuming a fix has shipped for their configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are there any other recommended actions to take?<\/h2>\n\n\n\n<p>Alongside remediation, defenders should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inventory all WebSphere traditional 9.0 and 8.5 instances reachable from the internet<\/li>\n\n\n\n<li>Restrict administrative console access to management networks or an authenticated VPN<\/li>\n\n\n\n<li>Block external traffic to <code>TCP\/9060<\/code> and <code>TCP\/9043<\/code> at the perimeter<\/li>\n\n\n\n<li>Monitor application server logs for deserialization errors and unexpected class loading<\/li>\n\n\n\n<li>Audit administrative role assignments for unauthorized privilege changes<\/li>\n\n\n\n<li>Review server logs for sensitive data written in the clear, per CVE-2026-14528<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How can CyCognito help your organization?<\/h2>\n\n\n\n<p>CyCognito published an Emerging Threat Advisory for CVE-2026-14512 and CVE-2026-14446 in the CyCognito platform and is actively researching enhanced detection capabilities for these vulnerabilities.<\/p>\n\n\n\n<p>To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, <a href=\"https:\/\/www.cycognito.com\/demo\/\">contact us to request a demo<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.<\/p>\n","protected":false},"author":39,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[250],"tags":[],"class_list":["post-2730","post","type-post","status-publish","format-standard","hentry","category-emerging-threats"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-29T14:03:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-29T14:03:46+00:00\" \/>\n<meta name=\"author\" content=\"Igal Zeifman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Igal Zeifman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\"},\"author\":{\"name\":\"Igal Zeifman\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\"},\"headline\":\"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation\",\"datePublished\":\"2026-07-29T14:03:45+00:00\",\"dateModified\":\"2026-07-29T14:03:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\"},\"wordCount\":746,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"articleSection\":[\"Emerging Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\",\"name\":\"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"datePublished\":\"2026-07-29T14:03:45+00:00\",\"dateModified\":\"2026-07-29T14:03:46+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\",\"name\":\"Igal Zeifman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"caption\":\"Igal Zeifman\"},\"description\":\"VP of Marketing\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog","og_description":"Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.","og_url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/","og_site_name":"CyCognito Blog","article_published_time":"2026-07-29T14:03:45+00:00","article_modified_time":"2026-07-29T14:03:46+00:00","author":"Igal Zeifman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Igal Zeifman","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/"},"author":{"name":"Igal Zeifman","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3"},"headline":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation","datePublished":"2026-07-29T14:03:45+00:00","dateModified":"2026-07-29T14:03:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/"},"wordCount":746,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"articleSection":["Emerging Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/","url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/","name":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"datePublished":"2026-07-29T14:03:45+00:00","dateModified":"2026-07-29T14:03:46+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-14512-cve-2026-14446-ibm-websphere-application-server-unauthenticated-code-execution-and-privilege-escalation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Emerging Threat: (CVE-2026-14512, CVE-2026-14446) IBM WebSphere Application Server Unauthenticated Code Execution and Privilege Escalation"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3","name":"Igal Zeifman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","caption":"Igal Zeifman"},"description":"VP of Marketing","url":"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=2730"}],"version-history":[{"count":1,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2730\/revisions"}],"predecessor-version":[{"id":2731,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2730\/revisions\/2731"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=2730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=2730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=2730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}