PatchSiren cyber security CVE debrief
CVE-2026-8850 IBM CVE debrief
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_ibm_upload module. The vulnerability, classified as CWE-476 (NULL Pointer Dereference), allows unauthenticated remote attackers to cause availability impact with high severity (CVSS 3.1: 7.5). The affected module is not enabled by default, reducing exposure for standard deployments. IBM has released security updates addressing this issue.
- Vendor
- IBM
- Product
- HTTP Server
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-07-23
Who should care
Organizations running IBM HTTP Server 8.5 or 9.0 with mod_ibm_upload enabled for file upload handling, particularly those with internet-facing web servers or multi-tenant hosting environments where availability is critical.
Technical summary
The vulnerability exists in the optional mod_ibm_upload module which provides file upload functionality for IBM HTTP Server. A NULL pointer dereference condition can be triggered remotely, resulting in server process termination and denial of service. The attack requires no authentication and can be executed over the network with minimal complexity. The module is optional and not loaded by default configurations, limiting the attack surface to deployments that have explicitly enabled this functionality.
Defensive priority
high
Recommended defensive actions
- Apply IBM HTTP Server fix packs 8.5.5.30 or 9.0.5.29 or later to remediate this vulnerability
- If immediate patching is not feasible, verify that mod_ibm_upload is not enabled in httpd.conf as a temporary risk reduction measure
- Monitor IBM support portal for additional security bulletins related to IBM HTTP Server components
- Review server configurations to confirm module loading status and document any custom upload handling implementations
Evidence notes
Vulnerability confirmed through NVD analysis with vendor advisory from IBM PSIRT. CPE configurations indicate affected versions with specific patch boundaries. CVSS vector confirms network attack vector with low complexity and no privileges required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8850 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8850
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8850 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8850
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7274065
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.