CyberICT

CVE-2026-11541

IBM · Published June 30, 2026

CVSS v3.1

CRITICAL

Description

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

Affected Products

  • Websphere Application Server < 8.5.5.31
  • Websphere Application Server < 9.0.5.29
  • Websphere Application Server <= 26.0.0.6

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H