PatchSiren cyber security CVE debrief
CVE-2026-8852 IBM CVE debrief
IBM HTTP Server versions 8.5 (prior to 8.5.5.30) and 9.0 (prior to 9.0.5.29) contain a denial-of-service vulnerability in the optional mod_fastcgi module. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates a local attack vector with low attack complexity, requiring no privileges or user interaction, resulting in high availability impact. The vulnerability is classified under CWE-617 (Reachable Assertion). IBM has released a vendor advisory with remediation guidance. No known exploitation in ransomware campaigns has been reported (KEV: false).
- Vendor
- IBM
- Product
- HTTP Server
- CVSS
- MEDIUM 6.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-07-23
Who should care
System administrators running IBM HTTP Server 8.5 or 9.0 with mod_fastcgi enabled; security teams responsible for web server infrastructure; organizations using IBM WebSphere Application Server which bundles IBM HTTP Server
Technical summary
The vulnerability exists in the optional mod_fastcgi module of IBM HTTP Server. A local attacker can trigger a denial-of-service condition without requiring privileges or user interaction. The high availability impact (A:H) suggests complete service disruption is possible. The local attack vector indicates the attacker must have some level of access to the target system, limiting remote exploitation risk.
Defensive priority
medium
Recommended defensive actions
- Review IBM HTTP Server deployments to identify systems running affected versions (8.5 prior to 8.5.5.30, 9.0 prior to 9.0.5.29)
- Verify whether the optional mod_fastcgi module is enabled in your configuration
- Apply the fixes or mitigation guidance provided in the IBM security advisory
- Monitor IBM support channels for additional updates to this advisory
Evidence notes
Vulnerability affects IBM HTTP Server 8.5.0.0 through versions before 8.5.5.30, and 9.0.0.0 through versions before 9.0.5.29. The mod_fastcgi module is described as optional, suggesting not all deployments are affected. CPE entries indicate the software runs on AIX, z/OS, Linux, and Windows platforms, though these operating systems themselves are not vulnerable.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7274065
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.