CVE-2026-8856: IBM HTTP Server
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
Affected products
- IBM HTTP Server: from 8.5.0.0, before 8.5.5.30 (fixed in 8.5.5.30); from 9.0.0.0, before 9.0.5.29 (fixed in 9.0.5.29)
Published 2026-05-26. Last modified 2026-07-23.