---
schema: 1
kind: vulnerability
title: "CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)"
headline: "CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)"
summary: "NCSC.ch's Security Hub flags CVE-2026-9170 — improper-input-validation pre-auth RCE in IBM HTTP Server / WebSphere at CVSS 9.8. Prevalent in Swiss banking, insurance and federal middleware estates; APAR PH71265 / Fix Pack updates are out."
discovered_at: "2026-05-29T05:00:09Z"
event_date: 2026-05-28
run_id: 2026-05-29-c7f56b00
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
regions:
  - europe
  - switzerland
  - global
sectors:
  - finance
  - public-sector
entities: []
cves:
  - id: CVE-2026-9170
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.ibm.com/support/pages/node/7274065"
    publisher: IBM Security Bulletin node/7274065
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12601"
    publisher: NCSC.ch Security Hub post 12601
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-9170 CVSS3.1: 9.8 (CRITICAL) - Improper input validation leading to RCE and DoS"
    publisher: NCSC.ch Security Hub post 12601
  - quote: IBM HTTP Server and WebSphere Application Server are vulnerable to remote code execution due to improper input validation
    publisher: IBM Security Bulletin
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-29.md
---

[IBM disclosed nine vulnerabilities in IBM HTTP Server (IHS) and WebSphere Application Server on 2026-05-26](https://www.ibm.com/support/pages/node/7274065); the most severe is `CVE-2026-9170` — CWE-94 improper input validation in the HTTP request-parsing layer that lets a remote, unauthenticated attacker trigger arbitrary code execution by sending a crafted HTTP request to the default web listener. [NCSC.ch flagged the advisory as Security Hub post 12601 on 2026-05-28](https://security-hub.ncsc.admin.ch/#/posts/12601). [NVD entry CVE-2026-9170](https://nvd.nist.gov/vuln/detail/CVE-2026-9170) carries the CVSS 9.8 base score. Affected: IBM HTTP Server 9.0 and 8.5 branches; WebSphere Application Server Traditional 9.0 and 8.5 before the listed fix packs. Other notable CVEs in the same batch: `CVE-2026-8855` (CVSS 8.1, RCE in TLS mutual-auth configs); `CVE-2026-8834` (CVSS 8.0, heap-based buffer overflow in the Administration Server); `CVE-2026-8856` / `CVE-2026-8850` / `CVE-2026-8854` (DoS). IBM recommends applying interim fix APAR PH71265 or the corresponding fix pack and disabling unused optional modules (`mod_ibm_upload`, `mod_mem_cache`). No public exploitation observed.
