Junglewise Threat Intelligence

CVE-2026-8855: IBM HTTP Server remote code execution in TLS mutual authentication

CVE-2026-8855 · Severity: high · CVSS 8.1 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a security flaw when configured to use mutual TLS authentication. An attacker could exploit this to crash the server or execute unauthorized commands, potentially leading to a full system takeover or service disruption. Organizations using client certificate authentication should apply the available security patches immediately.

Technical details

IBM HTTP Server (versions 8.5 and 9.0) contains a code injection vulnerability (CWE-94) within its TLS mutual authentication implementation. The vulnerability is triggered when the server is configured for client certificate authentication. Although the attack complexity is rated as high, a remote attacker can potentially achieve remote code execution or cause a denial of service (DoS) without prior authentication. IBM has released interim fix PH71265 to address this issue, with permanent fixes planned for fix packs 9.0.5.29 and 8.5.5.30.

Affected products

  • IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28

Timeline

  • 2026-05-26: disclosed: Initial publication of the security bulletin by IBM.
  • 2026-05-26: patched: Interim fix PH71265 released.

References