CVE-2026-11541
IBM · Published June 30, 2026
9.8
CVSS v3.1
CRITICALDescription
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
Affected Products
- Websphere Application Server < 8.5.5.31
- Websphere Application Server < 9.0.5.29
- Websphere Application Server <= 26.0.0.6
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H