CVE-2026-8855
published 2026-05-26CVE-2026-8855: IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.46%
37.2th percentile
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | http_server | — | — |
| ibm | http_server | 8.5.0 – Interim Fix 002 | — |
| ibm | http_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | http_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rjqm-vgmr-8cp8: IBM HTTP Server 8
ghsa_unreviewed·2026-05-26
CVE-2026-8855 [HIGH] CWE-94 GHSA-rjqm-vgmr-8cp8: IBM HTTP Server 8
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
VulDB
IBM HTTP Server 8.5/9.0 code injection
vuldb·2026-05-26·CVSS 9.8
CVE-2026-8855 [CRITICAL] IBM HTTP Server 8.5/9.0 code injection
A vulnerability described as critical has been identified in IBM HTTP Server 8.5/9.0. Affected by this issue is some unknown functionality. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-8855. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published