CVE-2026-9170: IBM HTTP Server is affected by multiple vulnerabilities
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM HTTP Server (used by IBM WebSphere Application Server) 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM HTTP Server (used by IBM WebSphere Application Server) 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71265 - Compensating control
For System z customers, subscribe to the System z Security Portal to receive the latest critical System z security and integrity service (so security and integrity APARs and associated fixes are posted to the portal).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9170?
The severity of CVE-2026-9170 is rated high with a score of 7.5.
What vulnerabilities are associated with CVE-2026-9170?
CVE-2026-9170 is associated with denial of service and potential remote code execution due to improper input validation.
How do I fix CVE-2026-9170?
To fix CVE-2026-9170, apply a currently available Web Server Plug-ins interim fix or fix pack that contains the fix for APAR PH71342.
Which software products are affected by CVE-2026-9170?
CVE-2026-9170 affects IBM Web Server Plug-ins for WebSphere Application Server and IBM WebSphere Application Server Liberty versions 8.5 and 9.0.
What is the impact of CVE-2026-9170?
The impact of CVE-2026-9170 includes potential denial of service and remote code execution exploiting improper input validation.