IBM disclosed CVE-2026-10842, a high-severity vulnerability with CVSS 7.5 that could let remote attackers bypass security constraints in WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7. The flaw, classified as Authentication Bypass by Alternate Name, was published to the NVD on July 30, 2026.

The description states that a remote attacker could exploit the vulnerability to bypass security constraints, potentially exposing confidential data given the high confidentiality impact.
Organizations running the listed versions of WebSphere Application Server should consult the IBM support page immediately.
Enterprise teams still running older WebSphere 8.5 and 9.0 instances face immediate exposure; patching or migration to a fixed release should be prioritized given the network-accessible nature of the bypass.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Anthropic has confirmed a worldwide outage affecting Claude and its API, with users receiving 529 Overloaded errors. The incident highlights the fragility of AI services that millions rely on for daily work.
CISA added CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities catalog on 2026-07-29. Federal agencies must remediate by 2026-08-01 per BOD 26-04 guidelines.
The Meta Box AIO WordPress plugin is vulnerable to missing authorization (CVE-2026-14488, CVSS 9.1) in versions up to 3.8.0, allowing unauthenticated attackers to delete arbitrary posts and pages via a bypassable nonce check. The flaw impacts any site with a frontend submission form regardless of delete settings.