Skip to content
Brief Security & Trust ·

HKCERT flags multiple flaws in IBM WebSphere products

A Hong Kong bulletin lists WebSphere Liberty versions before 26.0.0.10 as affected.

In brief
  • HKCERT says IBM WebSphere products have several flaws that a remote attacker could use. The bulletin is dated 8 October 2026.
  • It lists WebSphere Application Server Liberty versions before 26.0.0.10 as affected. It gives no flaw count or severity.

HKCERT published a security bulletin on 8 October 2026 about several flaws in IBM WebSphere products. It said a remote attacker could use some of them against a target system. The possible results are a denial of service, which blocks users from a service, and a gain in access rights. The flaws could also expose sensitive information or let an attacker change data. The bulletin names WebSphere Application Server Liberty, in versions before 26.0.0.10, as affected. It links to an IBM support page.

The bulletin does not say how many flaws there are. It gives no CVE numbers, which are the public IDs for known flaws. It does not rate their severity. It does not say which flaw causes which effect. HKCERT says only that some of them could be used this way. It does not say whether anyone is attacking these flaws now. The affected list names only Liberty, so the bulletin does not say whether other WebSphere products are hit. HKCERT tells readers to check the vendor's website for more detail.

Teams that run WebSphere Liberty can check their version against 26.0.0.10. They can then read IBM's page to see what applies to them.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: HKCERT, HKCERT, HKCERT.