← Vulnerability feed

Vulnerability record · CVE-2026-9170 · published 26 May 2026

CVE-2026-9170: Ibm http server code injection vulnerability

Ibm · Http Server

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

9.8 CVSS 3.1 Critical EPSS 0.86% · top 43.2% CWE-94 · Code injection
9.8CVSS 3.1 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
20 Jul 2026Last modified by NVD

Description

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-9170 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5955Ibm http server vulnerabilityUnspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute …EPSS 4.4%10.0CVE-2010-0425Apache mod_isapi on Windows remote code execution via orphaned callbacksmod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leavi…EPSS 94%analysed10.0CVE-2004-0492Apache http server vulnerabilityHeap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process cra…EPSS 34%9.8CVE-2026-8855Ibm http server code injection vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…EPSS 0.85%9.1CVE-2026-8856Ibm http server uncontrolled resource consumption vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…EPSS 0.34%9.0CVE-2015-4947Ibm http server memory buffer overflow vulnerabilityStack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.1…EPSS 7.9%8.0CVE-2026-8834Ibm http server heap-based buffer overflow vulnerabilityIBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit t…EPSS 0.34%7.5CVE-2026-8854Ibm http server vulnerabilityIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2026-9170), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.