CVE-2026-8856 – IBM HTTP Server
“Web server memory and code execution risks can expose core business services fast.”
IBM released patches for six high-severity vulnerabilities affecting HTTP Server. CVE-2026-8834 has a CVSS score of 8.0, which is High severity. CVE-2026-8855 has a CVSS score of 8.1, which is High severity. CVE-2026-8835 has a CVSS score of 7.3, which is High severity. CVE-2026-8850 has a CVSS score of 7.5, which is High severity. CVE-2026-8854 has a CVSS score of 7.5, which is High severity. CVE-2026-8856 has a CVSS score of 7.7, which is High severity.
The update addresses memory safety, code execution, null pointer, expired pointer, and resource consumption issues. Several vulnerabilities could allow remote code execution in affected IBM HTTP Server environments.
Key Details
- Affected Product
- Ibm Http Server
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-400