8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
Basic Information
ID
CVE-2026-8855
Source
ibm
Published
May 26, 2026 at 16:58
Affected Product
Vendor
IBM
Product
HTTP Server
Version
8.5.0
Affected Versions
IBM HTTP Server 8.5.0
IBM HTTP Server 9.0
IBM HTTP Server 9.0