This article addresses inquiries regarding the potential impact of Apache HTTP Server security vulnerabilities CVE-2026-4235 and CVE-2026-34355 on the Common Components and Services for z/OS (CCS) environment. It clarifies why these vulnerabilities do not affect the CCS (aka CA90s) product suite.
Product: Common Components and Services for z/OS
Component: CCS Tomcat
These vulnerabilities specifically target the Apache HTTP Server (`httpd`) and its associated modules (`mod_dav_fs` and `mod_proxy_html`).
You do not need to take any action for Common Components and Services for z/OS (CCS) regarding these CVEs.
For more information on Broadcom's response to security vulnerabilities, please refer to the Broadcom Security Advisory page.
If you require further assistance or wish to speak with a customer representative, see Contact Support. Scroll to the bottom of the page and click on your respective region.