SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16186

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM WebSphere Application Server versions 9.0 and 8.5 are vulnerable to a reflected cross-site scripting (XSS) flaw, which could allow an attacker to inject malicious scripts into web pages viewed by users. This vulnerability poses a risk of unauthorized actions being executed in the context of the affected user's session. Organizations using these versions of WebSphere should prioritize remediation to protect against potential exploitation and safeguard user data.

CVE
CVE-2026-16186
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.