Aix IBM Aix

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Aix.

By the Year

In 2026 there have been 145 vulnerabilities in IBM Aix with an average score of 7.8 out of ten. Last year, in 2025 Aix had 8 security vulnerabilities published. That is, 137 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 1.23




Year Vulnerabilities Average Score
2026 145 7.79
2025 8 9.03
2024 10 6.08
2023 12 6.99
2022 24 6.30
2021 9 6.22
2020 1 7.80
2019 0 0.00
2018 2 9.10

It may take a day or so for new Aix vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Aix Security Vulnerabilities

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Format String V local PrivEsc
CVE-2026-16821 7 - High - August 28, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.

Use of Externally-Controlled Format String

IBM AIX/VIOS LLBO: Local Attacker OOB Write via Faulty FS Image
CVE-2026-19783 6.7 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 cmdnim Lcl RCE to Root
CVE-2026-19449 8.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.

Improper Privilege Management

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 ESP Handler stack corruption
CVE-2026-19448 6.5 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.

Use of Uninitialized Resource

IBM AIX 7.x Remote UDP DoS via crafted packet
CVE-2026-19446 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.

Resource Exhaustion

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 vSCSI Pointer Validation Flaw
CVE-2026-19442 8.2 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.

Untrusted Pointer Dereference

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Code Exec via Buffer Overflow
CVE-2026-19437 8.1 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote Auth Cmd Exec via command injection
CVE-2026-18835 9.9 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM AIX 7.2/7.3 PowerVM VIOS 4.1: Local Code Exec via Pointer Validation
CVE-2026-18840 8.2 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.

Untrusted Pointer Dereference

IBM AIX 7+ OOB Write Enables Escalated Privileges (CVE-2026-18842)
CVE-2026-18842 8.4 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Heap Overflow RCE
CVE-2026-18832 8.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.

Memory Corruption

IBM AIX 7.2-7.3 / PowerVM VIOS 4.1 DoS via stack overflow
CVE-2026-18828 5.4 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

Memory Corruption

IBM AIX 7.2-7.3 & PowerVM VIOS 4.1: RCE via OS Command Injection
CVE-2026-18824 8.4 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM AIX 7.2/7.3 & VIOS 4.1 DoS via uncontrolled dir record parsing
CVE-2026-18822 4.4 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records.

Resource Exhaustion

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 OOB Read Enables Remote Info Disclosure
CVE-2026-18716 7.9 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Integer Underflow DoS
CVE-2026-18670 8.2 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.

Integer Overflow or Wraparound

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote RCE via Heap Buffer Overflow
CVE-2026-17436 8.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Stack Buffer Overflow Leading to DoS
CVE-2026-17425 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Pathname Bypass
CVE-2026-17424 4.8 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory.

Directory traversal

IBM AIX/PowerVM VIOS 7.2/7.3/4.1 OOB Read Info Leak & DoS
CVE-2026-17423 7.7 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

Buffer Overflow Exploit in AIX 7.2/7.3 & PowerVM VIOS 4.1
CVE-2026-17422 9.3 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Local DoS via OOB Write
CVE-2026-17195 6.5 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM 4.1 Local File Overwrite via Symlink
CVE-2026-17171 7.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.

insecure temporary file

DDoS via Allocation Size Validation in IBM AIX 7.27.3 & PowerVM VIOS 4.1
CVE-2026-17170 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.

Allocation of Resources Without Limits or Throttling

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Stack Buffer Overflow CVE-2026-17168
CVE-2026-17168 8.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: NULLptr DDoS via DS
CVE-2026-17165 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

NULL Pointer Dereference

IBM AIX 7.2/7.3 & VIOS 4.1 DoS via array size overvalidation
CVE-2026-17163 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field.

Allocation of Resources Without Limits or Throttling

IBM AIX 7.x Remote Code Exec: Integer Overflow in Size Compute
CVE-2026-17160 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.

Integer Overflow or Wraparound

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Integer Overflow DoS
CVE-2026-17159 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.

Integer Overflow or Wraparound

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 stack buffer overflow RCE
CVE-2026-17157 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX/PowerVM VIOS 7.2-7.3 & 4.1 Buffer Overflow RCE
CVE-2026-17152 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Code Exec via Privilege Mismanage
CVE-2026-17145 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.

Improper Privilege Management

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Command Execution via Improper Auth
CVE-2026-17142 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

authentification

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Buffer Overflow
CVE-2026-17141 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 RCE via Stack Buffer Overflow
CVE-2026-17138 8.1 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

Stack Overflow

Remote Code Exec: Format String in IBM AIX 7.2/7.3 & PowerVM VIOS
CVE-2026-17136 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.

Use of Externally-Controlled Format String

IBM AIX 7.2-7.3 / PowerVM VIOS 4.1 Local Code Exec via OOB Read
CVE-2026-17124 7.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 RCE via Stack Buffer Overflow
CVE-2026-17122 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Recursion DoS
CVE-2026-17121 7.5 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

Resource Exhaustion

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote DoS via Buffer Overflow
CVE-2026-17120 5.3 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Memory Corruption

IBM AIX 7.x & PowerVM VIOS 4.1: UAF RCE
CVE-2026-17118 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.

Dangling pointer

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Kernel Heap Over-Read Remote Info Leak & DoS
CVE-2026-17060 8.1 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read.

Information Disclosure

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Buffer Overflow RE Code Exec
CVE-2026-17040 9.8 - Critical - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Classic Buffer Overflow

IBM AIX 7.2-7.3 & PowerVM VIOS 4.1 RCE via Cert Validation
CVE-2026-17024 7.7 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.

Improper Certificate Validation

Local DoS via NULL Pointer Deref in IBM AIX 7.2-7.3 & PowerVM VIOS 4.1
CVE-2026-17009 4.7 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference.

NULL Pointer Dereference

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 OOB Read for Local Attacker
CVE-2026-17007 6.7 - Medium - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

Heap Overflow in IBM AIX 7.2-7.3 & PowerVM VIOS 4.1: Remote Code Exec
CVE-2026-17006 8.3 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

Memory Corruption

IBM AIX 7.2-7.3 & PowerVM VIOS 4.1 OOB Write Remote RCE
CVE-2026-17003 7.7 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote RCE via Invalid Auth
CVE-2026-17000 8.1 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication.

authentification

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 LPE via Improper Privilege Mgmt
CVE-2026-16997 7.8 - High - August 20, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management.

Improper Privilege Management

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Aix or by IBM? Click the Watch button to subscribe.

IBM
Vendor

IBM Aix
Product

subscribe