HKCERT published a security bulletin on 8 October 2026 about several flaws in IBM WebSphere products. It said a remote attacker could use some of them against a target system. The possible results are a denial of service, which blocks users from a service, and a gain in access rights. The flaws could also expose sensitive information or let an attacker change data. The bulletin names WebSphere Application Server Liberty, in versions before 26.0.0.10, as affected. It links to an IBM support page.
The bulletin does not say how many flaws there are. It gives no CVE numbers, which are the public IDs for known flaws. It does not rate their severity. It does not say which flaw causes which effect. HKCERT says only that some of them could be used this way. It does not say whether anyone is attacking these flaws now. The affected list names only Liberty, so the bulletin does not say whether other WebSphere products are hit. HKCERT tells readers to check the vendor's website for more detail.
Teams that run WebSphere Liberty can check their version against 26.0.0.10. They can then read IBM's page to see what applies to them.