SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-11707

CRITICAL · CVSS 9.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server are vulnerable to a critical cross-site scripting (XSS) flaw in their administrative console login page, which could allow attackers to execute arbitrary scripts in the context of the user's session. This vulnerability poses a significant risk as it can lead to unauthorized access and data compromise. Organizations using these products should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-11707
Severity
CRITICAL
CVSS
9.3
EPSS
0.22%

Original NVD Description

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

Related CVEs

Other vulnerabilities affecting the same vendor(s)