CVE-2026-11541

Summary

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.

Affected Software

VendorProductVersion RangeStatus
IBMCICS Transaction Gateway for Multiplatforms9.1affected
IBMCICS Transaction Gateway for Multiplatforms9.2affected
IBMCICS Transaction Gateway for Multiplatforms9.3affected
IBMCICS Transaction Gateway for Multiplatforms10.1affected

Weaknesses

  • CWE-444: CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References