IBM HTTP Server
9 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for IBM HTTP Server, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
IBM HTTP Server CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 6 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High6
- Medium1
Latest CVEs
The 9 most recently published vulnerabilities affecting IBM HTTP Server.
- CVE-2026-9170IBM HTTP Server is affected by multiple vulnerabilities9.8
- CVE-2026-8835IBM HTTP Server is affected by multiple vulnerabilities7.3
- CVE-2026-8834IBM HTTP Server is affected by multiple vulnerabilities8.0
- CVE-2026-8855IBM HTTP Server is affected by multiple vulnerabilities8.1
- CVE-2026-8854IBM HTTP Server is affected by multiple vulnerabilities7.5
- CVE-2026-8856IBM HTTP Server is affected by multiple vulnerabilities7.7
- CVE-2024-24795Apache HTTP Server: HTTP Response Splitting in multiple modules6.3
- CVE-2023-38709Apache HTTP Server: HTTP response splitting7.3
- CVE-2015-4947Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSpher...9.0
Product grouping is registry-driven, with AI assist and human review. How it works