CVE-2026-8854: IBM HTTP Server is affected by multiple vulnerabilities
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module modmemcache.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM HTTP Serverto a version that resolves this vulnerability.Fixed in 8.5.5.30Patch PH71265 - Upgrade
Upgrade
IBM HTTP Serverto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch PH71265 - Compensating control
Until the PH71265 interim fix/fix pack is applied, mitigate the denial-of-service exposure by removing or disabling the optional IBM HTTP Server module mod_mem_cache.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8854?
The severity of CVE-2026-8854 is rated high with a score of 7.5.
What does CVE-2026-8854 affect?
CVE-2026-8854 affects IBM HTTP Server versions 8.5 and 9.0, specifically via the mod_mem_cache module.
How does CVE-2026-8854 impact systems?
CVE-2026-8854 can lead to a denial of service vulnerability.
How do I fix CVE-2026-8854?
To fix CVE-2026-8854, apply the currently available interim fix or fix pack recommended by IBM.
Which versions of IBM HTTP Server are impacted by CVE-2026-8854?
IBM HTTP Server versions 8.5 and 9.0 are impacted by CVE-2026-8854.