CVE-2026-11541: Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms.
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 10.1.0.0to a version that resolves this vulnerability.Patch PH72094 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.1.0.0to a version that resolves this vulnerability.Patch PH72094 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.2.0.0to a version that resolves this vulnerability.Patch PH72094 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.3.0.0to a version that resolves this vulnerability.Patch PH72094 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 10.1.0.0to a version that resolves this vulnerability.Patch PH72095 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.1.0.0to a version that resolves this vulnerability.Patch PH72095 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.2.0.0to a version that resolves this vulnerability.Patch PH72095 - Upgrade
Upgrade
IBM CICS Transaction Gateway for Multiplatforms 9.3.0.0to a version that resolves this vulnerability.Patch PH72095 - Compensating control
If PSIRT fixes are required and you are not covered by Extended Support, note that PSIRT fixes for CICS Transaction Gateway for Multiplatforms will be provided only to customers covered by Extended Support and only upon request through an IBM Support case.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11541?
CVE-2026-11541 has a critical severity rating of 9.8.
How do I fix CVE-2026-11541?
To remediate CVE-2026-11541, update to the latest version of IBM WebSphere Application Server or Liberty as specified in the vendor's security advisory.
What systems are affected by CVE-2026-11541?
CVE-2026-11541 affects IBM WebSphere Application Server versions 8.5 and 9.0, along with IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.6.
What type of vulnerability is CVE-2026-11541?
CVE-2026-11541 is identified as an HTTP request smuggling vulnerability.
What impact does CVE-2026-11541 have on security?
The impact of CVE-2026-11541 includes potential unauthorized access to sensitive information and the ability to conduct further attacks based on the exploitation of the vulnerability.