Security Bulletin
Summary
IBM is providing security updates for supported AIX and VIOS releases that are under active fix support. Delivered through Service Packs (SPs) and Fix Packs (FPs), these updates remediate vulnerabilities affecting operating system, virtualization, and third-party components as described in the vulnerability details section. To simplify deployment and maintenance, the security fixes have been incorporated into cumulative maintenance packages. IBM strongly recommends that customers remain on supported releases and promptly apply all applicable security updates and fixes.
Vulnerability Details
CVEID: CVE-2026-18828
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
CVEID: CVE-2026-17138
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16885
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17118
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.
CWE: CWE-416: Use After Free
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17007
DESCRIPTION: AIX could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 6.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H)
CVEID: CVE-2026-17152
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16849
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary.
CWE: CWE-129: Improper Validation of Array Index
CVSS Source: IBM
CVSS Base score: 4.3
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-16838
DESCRIPTION: AIX could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.
CWE: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS Source: IBM
CVSS Base score: 7
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-15065
DESCRIPTION: IBM AIX NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.
CWE: CWE-312: Cleartext Storage of Sensitive Information
CVSS Source: IBM
CVSS Base score: 9.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVEID: CVE-2026-16891
DESCRIPTION: AIX could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 3.3
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-16926
DESCRIPTION: AIX could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
CWE: CWE-73: External Control of File Name or Path
CVSS Source: IBM
CVSS Base score: 9.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
CVEID: CVE-2026-17141
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16958
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16945
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16943
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-17159
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer overflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-8368
DESCRIPTION: LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes.
A redirect to an attacker controlled host therefore discloses the caller's credentials to that host.
CWE: CWE-522: Insufficiently Protected Credentials
CVSS Source: CISA ADP
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-16901
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17163
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper validation of an array size field.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16656
DESCRIPTION: IBM AIX could allow a remote attacker to gain root privileges due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-18840
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
CWE: CWE-822: Untrusted Pointer Dereference
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-17422
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.3
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16980
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to improper validation of symbolic links.
CWE: CWE-59: Improper Link Resolution Before File Access ('Link Following')
CVSS Source: IBM
CVSS Base score: 6.3
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H)
CVEID: CVE-2026-17142
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16991
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16831
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16937
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16877
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16914
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16862
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16883
DESCRIPTION: AIX could allow a local attacker to obtain sensitive information due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 5.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-16886
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 4.3
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-16964
DESCRIPTION: AIX could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-16844
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-18835
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 9.9
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16837
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16996
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an integer underflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-17006
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.3
CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-17122
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17195
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
CVEID: CVE-2026-16833
DESCRIPTION: AIX could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-2003
DESCRIPTION: Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CWE: CWE-1287: Improper Validation of Specified Type of Input
CVSS Source: Cisco
CVSS Base score: 4.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-2004
DESCRIPTION: Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CWE: CWE-1287: Improper Validation of Specified Type of Input
CVSS Source: Cisco
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-2005
DESCRIPTION: Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CWE: CWE-122: Heap-based Buffer Overflow
CVSS Source: Cisco
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-2006
DESCRIPTION: Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CWE: CWE-129: Improper Validation of Array Index
CVSS Source: Cisco
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16872
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16690
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16865
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to command injection.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16816
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 9.9
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-19448
DESCRIPTION: A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.
CWE: CWE-908: Use of Uninitialized Resource
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H)
CVEID: CVE-2026-59995
DESCRIPTION: sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CWE: CWE-23: Relative Path Traversal
CVSS Source: NVD
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L)
CVEID: CVE-2026-59996
DESCRIPTION: scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CWE: CWE-23: Relative Path Traversal
CVSS Source: NVD
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L)
CVEID: CVE-2026-59997
DESCRIPTION: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CWE: CWE-1284: Improper Validation of Specified Quantity in Input
CVSS Source: NVD
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-59999
DESCRIPTION: In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CWE: CWE-348: Use of Less Trusted Source
CVSS Source: NVD
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVEID: CVE-2026-60000
DESCRIPTION: sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source: NVD
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-60001
DESCRIPTION: sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source: cve@mitre.org
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
CVEID: CVE-2026-60002
DESCRIPTION: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CWE: CWE-416: Use After Free
CVSS Source: NVD
CVSS Base score: 9.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
CVEID: CVE-2026-16829
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
CWE: CWE-476: NULL Pointer Dereference
CVSS Source: IBM
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16944
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-19449
DESCRIPTION: AIX has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16850
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17160
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16972
DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
CVEID: CVE-2026-17423
DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 7.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
CVEID: CVE-2026-17165
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
CWE: CWE-476: NULL Pointer Dereference
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16839
DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 9.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H)
CVEID: CVE-2026-17170
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16703
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-18822
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 4.4
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16819
DESCRIPTION: AIX could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.
CWE: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS Source: IBM
CVSS Base score: 7.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
CVEID: CVE-2026-16824
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to unbounded recursion.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-18824
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16814
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16973
DESCRIPTION: AIX could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: IBM
CVSS Base score: 5.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-18842
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.4
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17124
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16874
DESCRIPTION: AIX could allow a local attacker to obtain root privileges due to improper enforcement of RBAC authentication roles.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-41254
DESCRIPTION: Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CWE: CWE-696: Incorrect Behavior Order
CVSS Source: NVD
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-47057
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: secalert_us@oracle.com
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-47063
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVEID: CVE-2026-47058
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data.
CWE: CWE-502: Deserialization of Untrusted Data
CVSS Source: secalert_us@oracle.com
CVSS Base score: 7.4
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
CVEID: CVE-2026-60147
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-46968
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 5.9
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVEID: CVE-2026-47027
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-47021
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: secalert_us@oracle.com
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-47059
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 3.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-47010
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE.
CWE: CWE-284: Improper Access Control
CVSS Source: secalert_us@oracle.com
CVSS Base score: 3.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVEID: CVE-2026-8400
DESCRIPTION: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
CWE: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16439
DESCRIPTION: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
CWE: CWE-124: Buffer Underwrite ('Buffer Underflow')
CVSS Source: NVD
CVSS Base score: 9.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
CVEID: CVE-2026-16441
DESCRIPTION: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.
CWE: CWE-758: Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVSS Source: emo@eclipse.org
CVSS Base score: 6.9
CVSS Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
CVEID: CVE-2026-16243
DESCRIPTION: In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: NVD
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-19442
DESCRIPTION: AIX has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
CWE: CWE-822: Untrusted Pointer Dereference
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16924
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
CWE: CWE-191: Integer Underflow (Wrap or Wraparound)
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16903
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.6
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16935
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
CWE: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-15068
DESCRIPTION: AIX NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 9.9
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16911
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-121: Stack-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-15078
DESCRIPTION: AIX NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.
CWE: CWE-295: Improper Certificate Validation
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
CVEID: CVE-2026-16989
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
CWE: CWE-59: Improper Link Resolution Before File Access ('Link Following')
CVSS Source: IBM
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
CVEID: CVE-2026-16706
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16686
DESCRIPTION: AIX could allow a remote attacker to access NFS-exported filesystems due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)
CVEID: CVE-2026-8829
DESCRIPTION: HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.
The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.
The read may disclose adjacent heap contents into the destination SV.
CWE: CWE-416: Use After Free
CVSS Source: CISA ADP
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-16927
DESCRIPTION: AIX could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
CWE: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS Source: IBM
CVSS Base score: 7.3
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16894
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16909
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.
CWE: CWE-128: Wrap-around Error
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-15061
DESCRIPTION: AIX's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
CWE: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L)
CVEID: CVE-2026-16873
DESCRIPTION: AIX could allow a local attacker to achieve local privilege escalation due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17120
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-16888
DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.
CWE: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source: IBM
CVSS Base score: 3.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-17157
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16822
DESCRIPTION: AIX could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
CWE: CWE-295: Improper Certificate Validation
CVSS Source: IBM
CVSS Base score: 9.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N)
CVEID: CVE-2026-17060
DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
CVEID: CVE-2026-48959
DESCRIPTION: IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.
fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.
Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip-new($zip, Name = $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.
CWE: CWE-407: Inefficient Algorithmic Complexity
CVSS Source: CISA ADP
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-17136
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
CWE: CWE-134: Use of Externally-Controlled Format String
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16864
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16866
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 4.8
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
CVEID: CVE-2026-16857
DESCRIPTION: AIX could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L)
CVEID: CVE-2026-17145
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper privilege management.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-6472
DESCRIPTION: Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-862: Missing Authorization
CVSS Source: PostgreSQL
CVSS Base score: 5.4
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-6473
DESCRIPTION: Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: PostgreSQL
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-6474
DESCRIPTION: Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-134: Use of Externally-Controlled Format String
CVSS Source: PostgreSQL
CVSS Base score: 4.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-6475
DESCRIPTION: Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-61: UNIX Symbolic Link (Symlink) Following
CVSS Source: PostgreSQL
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-6477
DESCRIPTION: Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-242: Use of Inherently Dangerous Function
CVSS Source: PostgreSQL
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-6478
DESCRIPTION: Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-385: Covert Timing Channel
CVSS Source: PostgreSQL
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-6637
DESCRIPTION: Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CWE: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS Source: PostgreSQL
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16934
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16827
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
CWE: CWE-908: Use of Uninitialized Resource
CVSS Source: IBM
CVSS Base score: 5.9
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16928
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
CWE: CWE-122: Heap-based Buffer Overflow
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-18670
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 8.2
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
CVEID: CVE-2026-16932
DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-17168
DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.5
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-19446
DESCRIPTION: AIX allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-17425
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16846
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a null pointer dereference.
CWE: CWE-476: NULL Pointer Dereference
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16825
DESCRIPTION: AIX could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 4.2
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L)
CVEID: CVE-2026-16890
DESCRIPTION: AIX could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 3.6
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L)
CVEID: CVE-2026-16840
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16875
DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16821
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a format string vulnerability.
CWE: CWE-134: Use of Externally-Controlled Format String
CVSS Source: IBM
CVSS Base score: 7
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16836
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-18832
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16847
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16922
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
CWE: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS Source: IBM
CVSS Base score: 7
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16848
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16869
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.
CWE: CWE-426: Untrusted Search Path
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-22016
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: secalert_us@oracle.com
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-22021
DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: secalert_us@oracle.com
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-22013
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data.
CWE: CWE-693: Protection Mechanism Failure
CVSS Source: secalert_us@oracle.com
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
CVEID: CVE-2026-22018
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
CVSS Source: secalert_us@oracle.com
CVSS Base score: 3.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-34268
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: secalert_us@oracle.com
CVSS Base score: 2.9
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-22007
DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data.
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVSS Source: secalert_us@oracle.com
CVSS Base score: 2.9
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
CVEID: CVE-2026-16919
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
CWE: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16841
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2025-12818
DESCRIPTION: Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: PostgreSQL
CVSS Base score: 5.9
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-17009
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to a NULL pointer dereference.
CWE: CWE-476: NULL Pointer Dereference
CVSS Source: IBM
CVSS Base score: 4.7
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-17003
DESCRIPTION: AIX could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 7.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L)
CVEID: CVE-2026-16925
DESCRIPTION: AIX could allow a local attacker to achieve privilege escalation due to improper authorization.
CWE: CWE-285: Improper Authorization
CVSS Source: IBM
CVSS Base score: 7.1
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
CVEID: CVE-2026-17000
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper authentication.
CWE: CWE-287: Improper Authentication
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-14970
DESCRIPTION: IBM AIX NIM server process is crashing during client registration due to buffer overflow.
CWE: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16913
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16834
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer underflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17171
DESCRIPTION: AIX could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
CWE: CWE-59: Improper Link Resolution Before File Access ('Link Following')
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16936
DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVEID: CVE-2026-16923
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7
CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16997
DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to improper privilege management.
CWE: CWE-269: Improper Privilege Management
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16882
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16897
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to an out-of-bounds write.
CWE: CWE-369: Divide By Zero
CVSS Source: IBM
CVSS Base score: 4.4
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16946
DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 7.8
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17424
DESCRIPTION: AIX could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.
CWE: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source: IBM
CVSS Base score: 4.8
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVEID: CVE-2026-16845
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16818
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16917
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an integer overflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16855
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to a heap buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 5.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-17121
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-12087
DESCRIPTION: Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: CISA ADP
CVSS Base score: 9.1
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
CVEID: CVE-2026-17024
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper certificate validation.
CWE: CWE-295: Improper Certificate Validation
CVSS Source: IBM
CVSS Base score: 7.7
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H)
CVEID: CVE-2025-15649
DESCRIPTION: IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.
_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.
The exception propagates out of IO::Uncompress::Unzip-new($file) where callers expect undef plus $UnzipError.
CWE: CWE-248: Uncaught Exception
CVSS Source: CISA ADP
CVSS Base score: 5.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-48962
DESCRIPTION: IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.
_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.
Arbitrary Perl in the output glob executes at the calling process's privilege.
CWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CVSS Source: CISA ADP
CVSS Base score: 7.3
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVEID: CVE-2026-16842
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-19783
DESCRIPTION: IBM AIX could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17436
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.8
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-17040
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS Source: IBM
CVSS Base score: 9.8
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2025-12817
DESCRIPTION: Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
CWE: CWE-862: Missing Authorization
CVSS Source: PostgreSQL
CVSS Base score: 3.1
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)
CVEID: CVE-2026-19653
DESCRIPTION: PowerVM VIOS could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 6.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
CVEID: CVE-2026-18716
DESCRIPTION: AIX could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
CWE: CWE-125: Out-of-bounds Read
CVSS Source: IBM
CVSS Base score: 7.9
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H)
CVEID: CVE-2026-16951
DESCRIPTION: AIX could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 6.7
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2026-16852
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer overflow.
CWE: CWE-190: Integer Overflow or Wraparound
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16952
DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400: Uncontrolled Resource Consumption
CVSS Source: IBM
CVSS Base score: 5.5
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-16851
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a use-after-free.
CWE: CWE-416: Use After Free
CVSS Source: IBM
CVSS Base score: 7.4
CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
CVEID: CVE-2026-16817
DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.
CWE: CWE-476: NULL Pointer Dereference
CVSS Source: IBM
CVSS Base score: 7.5
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID: CVE-2026-19437
DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow.
CWE: CWE-787: Out-of-bounds Write
CVSS Source: IBM
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Products and Versions
| Affected Product(s) | Version(s) |
| AIX | 7.2 |
| AIX | 7.3 |
| PowerVM VIOS | 4.1 |
The vulnerabilities in the following filesets are being addressed:
key_fileset = aix
| Fileset | Lower Level | Upper Level | KEY |
| bos.mp64 | 7.2.5.0 | 7.2.5.212 | key_w_fs |
| bos.mp64 | 7.3.2.0 | 7.3.2.5 | key_w_fs |
| bos.mp64 | 7.3.3.0 | 7.3.3.2 | key_w_fs |
| bos.mp64 | 7.3.4.0 | 7.3.4.1 | key_w_fs |
To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in AIX user's guide.
Example: lslpp -L | grep -i bos.mp64
Remediation/Fixes
A. APARS
IBM has assigned the following APARs to this problem:
| AIX Level | APAR | Availability | SP | KEY |
| 7.2.5 | IJ59566 | 08/14/2026 | SP13 | key_w_apar |
| 7.3.2 | IJ59565 | 08/14/2026 | SP05 | key_w_apar |
| 7.3.3 | IJ59564 | 08/14/2026 | SP03 | key_w_apar |
| 7.3.4 | IJ59563 | 08/14/2026 | SP02 | key_w_apar |
| VIOS Level | APAR | Availability | SP | KEY |
| 4.1.0 | IJ59565 | 08/14/2026 | 4.1.0.50 | key_w_apar |
| 4.1.1 | IJ59564 | 08/14/2026 | 4.1.1.30 | key_w_apar |
| 4.1.2 | IJ59563 | 08/14/2026 | 4.1.2.20 | key_w_apar |
B. FIXES
IBM strongly recommends addressing the vulnerability now.
AIX and VIOS fixes are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral
An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update can be used to avoid a reboot.
IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities.
| AIX Level | Service Pack |
| AIX 7.3 TL04 | SP2 |
| AIX 7.3 TL03 | SP3 |
| AIX 7.3 TL02 | SP5 |
| AIX 7.2 TL05 | SP13 |
| PowerVM VIOS Level | Fix Pack |
| VIOS 4.1.2 | 4.1.2.20 |
| VIOS 4.1.1 | 4.1.1.30 |
| VIOS 4.1.0 | 4.1.0.50 |
Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL .
Note: To apply these patches using nimsh secure, special steps must be taken as the protocol between master and client is updated to be more secure. Please read this article:
https://www.ibm.com/support/pages/node/7283157
Note: For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs above. Instructions to do that can be found here:
4.1.0.50 post-update instructions: https://www.ibm.com/support/pages/node/7283819
4.1.1.30 post-update instructions: https://www.ibm.com/support/pages/node/7283823
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Acknowledgement
CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).
Change History
15 Aug 2026: Initial Publication
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to address potential vulnerabilities, IBM periodically updates the record of components contained in our product offerings. As part of that effort, if IBM identifies previously unidentified packages in a product/service inventory, we address relevant vulnerabilities regardless of CVE date. Inclusion of an older CVEID does not demonstrate that the referenced product has been used by IBM since that date, nor that IBM was aware of a vulnerability as of that date. We are making clients aware of relevant vulnerabilities as we become aware of them. "Affected Products and Versions" referenced in IBM Security Bulletins are intended to be only products and versions that are supported by IBM and have not passed their end-of-support or warranty date. Thus, failure to reference unsupported or extended-support products and versions in this Security Bulletin does not constitute a determination by IBM that they are unaffected by the vulnerability. Reference to one or more unsupported versions in this Security Bulletin shall not create an obligation for IBM to provide fixes for any unsupported or extended-support products or versions.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
15 August 2026
Initial Publish date:
15 August 2026
UID
ibm17283858