CVE-2026-8852: IBM HTTP Server is affected by multiple vulnerabilities
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module modfastcgi module.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71265 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.5.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.5.29
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8852?
CVE-2026-8852 has a medium severity rating of 6.2.
How do I fix CVE-2026-8852?
To fix CVE-2026-8852, apply the available interim fix or fix pack that addresses the issue related to APAR PH71265.
What types of attacks can CVE-2026-8852 facilitate?
CVE-2026-8852 can facilitate denial-of-service attacks via the mod_fastcgi module.
Which versions of IBM HTTP Server are affected by CVE-2026-8852?
IBM HTTP Server versions 8.5 and 9.0 are affected by CVE-2026-8852.
Is the exploit of CVE-2026-8852 remote or local?
The exploit of CVE-2026-8852 is a remote attack vector.