CVE-2026-11548 PUBLISHED

Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.

Assigner: ibm
Reserved: 08.06.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.8

Product Status

Vendor IBM
Product CICS TX Advanced
Versions
  • Version 10.1 is affected

Solutions

IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix.

ProductVersionPlatformRemediation/FixIBM CICS TX Advanced10.1Linux

Download and apply the update from  Fix Central https://www.ibm.com/support/fixcentral/quickorder

References

Problem Types

  • CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE