Junglewise Threat Intelligence

CVE-2026-8854: IBM HTTP Server denial of service in mod_mem_cache

CVE-2026-8854 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a denial of service attack. An attacker can exploit this flaw to crash the server, making hosted websites and applications unavailable to legitimate users. This impact is limited to systems using the optional memory caching module.

Technical details

IBM HTTP Server is vulnerable to an expired pointer dereference (CWE-825) within the optional mod_mem_cache module. A remote, unauthenticated attacker can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to cause a denial of service by crashing the server process. The vulnerability affects versions 8.5 and 9.0; IBM has released interim fix PH71265 and recommends upgrading to fix packs 8.5.5.30 or 9.0.5.29.

Affected products

  • IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Interim fix PH71265 released

References