CVE-2026-11541
published 2026-06-30CVE-2026-11541: IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server -…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.42%
35.6th percentile
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cics_transaction_gateway_for_multiplatforms | — | — |
| ibm | cics_transaction_gateway_for_multiplatforms | — | — |
| ibm | cics_transaction_gateway_for_multiplatforms | — | — |
| ibm | cics_transaction_gateway_for_multiplatforms | — | — |
| ibm | websphere_application_server | 17.0.0.3 – 26.0.0.6 | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.31 | 8.5.5.31 |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM WebSphere Application Server 8.5/9.0 request smuggling
vuldb·2026-07-30·CVSS 9.8
CVE-2026-11541 [CRITICAL] IBM WebSphere Application Server 8.5/9.0 request smuggling
A vulnerability categorized as problematic has been discovered in IBM WebSphere Application Server 8.5/9.0. This issue affects some unknown processing. The manipulation results in http request smuggling.
This vulnerability is known as CVE-2026-11541. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
ghsa_unreviewed·2026-07-01
CVE-2026-11541 [HIGH] CWE-444 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published