← Browse

CVE-2026-8855

Medium

Elevated severity or exploit probability.

CVSS base
8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.8%
56.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-94
Published 2026-05-26 · modified 2026-07-23

Description

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

Affected

ibm linux microsoft

References

Official: NVD · CVE.org