SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15634

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5, as well as IBM WebSphere Application Server - Liberty, are vulnerable to HTTP request smuggling due to improper parsing of the HTTP transfer-encoding request header. An attacker can exploit this vulnerability to poison web caches, bypass web application firewalls, and potentially execute cross-site scripting (XSS) attacks. Organizations using these versions should prioritize remediation to mitigate the risk of cache poisoning and related attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15634
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.