# IBM QRadar, WebSphere Patch Multiple Flaws

Published: 2026-07-10 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/c0344eb4-9861-5c5d-b328-ad456ed4c3fc/ibm-qradar-websphere-patch-multiple-flaws

> ANSSI advisory details multiple vulnerabilities in IBM QRadar App SDK and WebSphere products enabling DoS, data disclosure, and SSRF.

CERT-FR issued an advisory covering multiple vulnerabilities discovered in IBM products, including QRadar App SDK, WebSphere Application Server Liberty, WebSphere Hybrid Edition, and WebSphere Remote Server. The flaws span several vulnerability classes including remote denial of service, confidentiality breaches, server-side request forgery (SSRF), security policy bypass, and indirect remote code injection (XSS).

Affected versions include QRadar App SDK prior to 2.2.5, WebSphere Application Server Liberty prior to 26.0.0.8, WebSphere Hybrid Edition 5.1 without a set of listed security fixes, and WebSphere Remote Server 8.5.x prior to 8.5.5.31 and 9.x prior to 9.0.5.29. IBM has published a series of security bulletins detailing patches for the affected products, and organizations running these versions should apply the referenced fixes per IBM guidance. No active exploitation is indicated in the advisory; this is a routine patch notification covering numerous CVEs.

## Mentioned in this report

- Vulnerabilities: CVE-2024-29371, CVE-2025-66418, CVE-2025-66471, CVE-2025-69277, CVE-2026-11383, CVE-2026-11541, CVE-2026-11546, CVE-2026-11594, CVE-2026-11595, CVE-2026-11707, CVE-2026-11708, CVE-2026-11712, CVE-2026-11714, CVE-2026-11806, CVE-2026-21441, CVE-2026-26007, CVE-2026-34073, CVE-2026-39892, CVE-2026-50645, CVE-2026-9171, CVE-2026-9322, CVE-2026-9563

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0865

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c0344eb4-9861-5c5d-b328-ad456ed4c3fc/ibm-qradar-websphere-patch-multiple-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
