CVE-2026-11722: Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
Published Sep 16, 2026
·Updated
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Affected Software
1 affected componentFixes available
IBM CICS TX Advanced<=10.1
Event History
Sep 16, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Are specific affected versions identified?
No affected version numbers are provided in the available data. Review the IBM support reference for version-specific applicability and remediation guidance.
2
Does the available information describe exploit prerequisites or temporary mitigations?
No. The data identifies the issue as HTTP request smuggling but does not state attacker access requirements, configuration conditions, or compensating controls.