IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7274065 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
26 May 2026, 20:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ibm z\/os
Linux linux Kernel Microsoft windows Ibm aix Ibm http Server Ibm Linux Microsoft |
|
| CPE | cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7274065 - Vendor Advisory |
26 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-26 18:16
Updated : 2026-05-26 20:25
NVD link : CVE-2026-8855
Mitre link : CVE-2026-8855
CVE.ORG link : CVE-2026-8855
JSON object : View
Products Affected
microsoft
- windows
ibm
- aix
- z\/os
- http_server
linux
- linux_kernel
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
