CVE-2026-9170: IBM HTTP Server

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Affected products

  • IBM HTTP Server: version 8.5.0.0 only; version 9.0.0.0 only

Published 2026-05-26. Last modified 2026-07-20.