Denial of Service in IBM HTTP Server Products
CVE-2026-8856

7.7HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
26 May 2026

What is CVE-2026-8856?

IBM HTTP Server versions 8.5 and 9.0 are susceptible to a denial of service vulnerability if an attacker can modify server configuration files. This can lead to disruptions in service availability, making it crucial for organizations using these versions to review their access controls and implement applicable patches to safeguard their systems.

Affected Version(s)

HTTP Server 8.5.0

HTTP Server 9.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.