Summary
CVE-2026-9072 is a high-severity Code Injection vulnerability (CWE-94) affecting IBM WebSphere Application Server (versions 8.5 and 9.0), IBM WebSphere Application Server Liberty, and IBM i (versions 7.3–7.6), when the Intelligent Management feature is enabled alongside the WebSphere WebServer Plug-in component. A remote, unauthenticated attacker who can impersonate backend WebSphere Application Server instances can send crafted responses to the plug-in, leading to remote code execution (RCE) or denial of service (DoS). IBM assigned a CVSS v3.1 base score of 8.1 (High).
Technical details
- Root cause: CWE-94 – Improper Control of Generation of Code (Code Injection). The WebSphere WebServer Plug-in component does not safely process responses received from backend servers, allowing attacker-supplied content to influence code execution paths within the plug-in.
- Trigger conditions: The Intelligent Management feature must be enabled with the WebSphere WebServer Plug-in component configured. This is not a default configuration; however, deployments using IBM’s Intelligent Management topology are directly affected.
- Attack vector: Network-based. An attacker capable of impersonating backend WebSphere Application Server instances — for example, through a man-in-the-middle position on the network path between the plug-in and its backend servers — sends specially crafted responses to the plug-in. No privileges or user interaction are required.
- Impact: Successful exploitation can result in arbitrary remote code execution or denial of service on the host running the plug-in, with full impact to confidentiality, integrity, and availability (C:H/I:H/A:H).
Affected software
- IBM WebSphere Application Server 9.0.0.0 through 9.0.5.27 — when using Intelligent Management with the WebSphere WebServer Plug-in
- IBM WebSphere Application Server 8.5.0.0 through 8.5.5.29 — when using Intelligent Management with the WebSphere WebServer Plug-in
- IBM WebSphere Application Server Liberty (versions 8.5 and 9.0) — when using Intelligent Management with the WebSphere WebServer Plug-in
- IBM i 7.3, 7.4, 7.5, and 7.6 (5770-SS1 Option 3 – Web Server Plug-ins) — when using Intelligent Management with the WebSphere WebServer Plug-in
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- IBM WebSphere Application Server 9.0: Apply the Web Server Plug-ins Interim Fix resolving APAR PH71376 at the applicable fix pack level, or upgrade to Fix Pack 9.0.5.28 or later once available.
- IBM WebSphere Application Server 8.5: Apply the Web Server Plug-ins Interim Fix resolving APAR PH71376 at the applicable fix pack level, or upgrade to Fix Pack 8.5.5.30 or later once available.
- IBM i 7.6: Apply PTF SJ10122
- IBM i 7.5: Apply PTF SJ10121
- IBM i 7.4: Apply PTF SJ10120
- IBM i 7.3: Apply PTF SJ10119
- IBM has not documented any workaround for this vulnerability. Where immediate patching is not possible, organizations should evaluate whether Intelligent Management can be temporarily disabled, and should apply strict network-layer controls to limit the plug-in’s exposure to untrusted network segments.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

