Back to CVE database
CVE-2026-16189
medium · CVSS 4.8Published 9/14/2026 at 08:16 PMCWE-117
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative lo…
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
Why it matters
Internet-facing
Not identified as a common internet-facing category
Exploitation likelihood
high
- ▸ Remotely exploitable over the network — no physical or local access required
- ▸ High attack complexity — exploitation requires specific conditions
- ▸ No authentication required
- ▸ No user interaction needed — can be exploited automatically
Recommended mitigation
Apply the vendor patch as soon as it's available or already released.
This analysis is generated from structured CVSS vector data, CISA KEV cross-referencing, and vendor/product category rules — not a manual expert review. Treat it as a starting point, not a substitute for your own assessment.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Complexity
High
Privileges Req.
None
User Interaction
None
EU Vulnerability Database (ENISA)
EUVD ID
EUVD-2026-77800
EUVD is ENISA's EU vulnerability database, still in beta. EPSS is a probabilistic exploitation-likelihood score, not a certainty.
Stay Updated
New CVEs and vulnerability advisories are added continuously as they're disclosed. Subscribe via RSS to get every update the moment it's published — no email or account required.
Subscribe via RSS