CVE-2026-11541: IBM WebSphere Application Server
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Affected products
- IBM WebSphere Application Server: from 8.5.0.0, before 8.5.5.31 (fixed in 8.5.5.31); from 9.0.0.0, before 9.0.5.29 (fixed in 9.0.5.29); from 17.0.0.3, up to and including 26.0.0.6
Published 2026-06-30. Last modified 2026-07-29.