IBM I
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM I.
By the Year
In 2026 there have been 113 vulnerabilities in IBM I with an average score of 7.1 out of ten. Last year, in 2025 I had 14 security vulnerabilities published. That is, 99 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.01.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 113 | 7.07 |
| 2025 | 14 | 7.06 |
| 2024 | 12 | 6.37 |
| 2023 | 13 | 7.48 |
| 2022 | 6 | 4.83 |
| 2021 | 30 | 6.10 |
| 2020 | 10 | 4.63 |
| 2019 | 27 | 6.00 |
| 2018 | 78 | 0.00 |
It may take a day or so for new I vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM I Security Vulnerabilities
Remote Authenticated Info Disclosure via XML External Entities in IBM i 7.6-7.3
CVE-2026-18715
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.
XXE
IBM i 7.6/7.5/7.4/7.3 NetServer Int Overflow DoS
CVE-2026-18671
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.
Integer Overflow or Wraparound
IBM i 7.6-7.3 JSSE provider stack overflow via TLS session
CVE-2026-18511
7.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
Memory Corruption
IBM i 7.x local auth privilege escalation via Navigator for i debugger
CVE-2026-18509
8.2 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
AuthZ
IBM i 7.6/7.5/7.4/7.3 Exp Lev via Java Ptr Validation Fault
CVE-2026-18249
8.4 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
Improper Privilege Management
IBM i 7.x CVE-2026-18193: Remote Bypass via Addr Validation
CVE-2026-18193
8.9 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
Improper Privilege Management
IBM i 7.x Thread Authority Swap Local Priv Esc
CVE-2026-18101
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.
Improper Privilege Management
IBM i 7.6-7.3 Local Arbitrary Code/DoS via Improper Bounds Check
CVE-2026-18086
4.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
Memory Corruption
IBM i 7.x Stack Buffer Overflow Culminates in DoS via Remote Attack
CVE-2026-18077
7.5 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
Memory Corruption
IBM i 7.6/7.5/7.4/7.3 Info Disclosure via Byte-Count Confusion
CVE-2026-18068
4.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
Information Disclosure
IBM i Off-by-One Bounds Checking DoS in 7.6/7.5/7.4/7.3
CVE-2026-18020
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
Out-of-bounds Read
IBM i OOB Read Vulnerability (CVE-2026-17649)
CVE-2026-17649
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.6-7.3 Remote DoS via OutofBounds Write
CVE-2026-17502
8.6 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Memory Corruption
IBM i 7.6/7.5/7.4/7.3 Remote DoS via improper buffer write
CVE-2026-17476
4.8 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Memory Corruption
IBM i 7.6-7.3 Local Privilege Escalation via Improper Privilege Management
CVE-2026-17438
4.4 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
Improper Privilege Management
IBM i Auth Token Validation Flaw 7.6/7.5/7.4/7.3 Remote Info Disclosure
CVE-2026-17075
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
authentification
IBM i Remote DoS via Buffer Overflow (v7.3-7.6)
CVE-2026-17272
8.2 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Memory Corruption
IBM i 7.6: OOB Read Enables Remote Authenticated Info Leakage & DoS
CVE-2026-17226
5.4 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Out-of-bounds Read
IBM i (pre-8.0) DRDA LO header integer error leads to DoS
CVE-2026-17216
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.
Integer Overflow or Wraparound
IBM i OOB Read DoS 7.6, 7.5, 7.4, 7.3
CVE-2026-17212
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.3-7.6 Auth Bypass RCE & Info Leak
CVE-2026-17101
8.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
authentification
IBM i 7.67.3 Improper Auth Enables Remote Info Disclosure
CVE-2026-17099
7.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
authentification
IBM i 7.67.3 Path Traversal Enables Remote Info Disclosure
CVE-2026-17088
4.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Directory traversal
IBM i 7.x DoS via Resource Exhaustion
CVE-2026-17078
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
Resource Exhaustion
IBM i 7.37.6 Remote DoS via Uninitialized Variable
CVE-2026-17077
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.
Use of Uninitialized Variable
IBM i Pre-7.7 DRDA/DDM Resync Defect Causing Remote DOS
CVE-2026-17076
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.
Allocation of Resources Without Limits or Throttling
IBM i 7.3-7.6 Authenticated Priv Escalation via Improper Priv Mgmt
CVE-2026-17074
3.1 - Low
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.
Improper Privilege Management
IBM i 7.6/7.5/7.4/7.3 Path Traversal allows Remote Auth File Manipulation
CVE-2026-17071
2.7 - Low
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.
Directory traversal
IBM i 7.67.3 CSRF Token Validation Bypass for Authenticated Attacker
CVE-2026-17069
8.1 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
Session Riding
IBM i 7.3-7.6 Unauthorized Ops via Improper Session Mgmt
CVE-2026-17045
8.1 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
Authentication Bypass by Capture-replay
Remote Authenticated Deletion via Path Traversal in IBM i 7.6/7.5/7.4/7.3
CVE-2026-17043
3.8 - Low
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Directory traversal
IBM i 7.6/7.5/7.4/7.3 Local OOB Write Arbitrary Code Execution
CVE-2026-17029
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
Memory Corruption
IBM i 7.6/7.5/7.4/7.3: Priv Escalation via LANG Env Var
CVE-2026-16987
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
External Control of File Name or Path
IBM i 7.6-7.3 Heap Buffer Overflow RCE Remote Authenticated
CVE-2026-16975
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
Memory Corruption
IBM i 7.x TOCTOU Symlink Race Allows Unauthorized Access
CVE-2026-16967
8.5 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
TOCTTOU
IBM i 7.6/7.5/7.4 SQLi Vulnerability
CVE-2026-16961
7.6 - High
- August 13, 2026
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
SQL Injection
IBM i 7.6/7.5/7.4/7.3 Remote AuthID Path Traversal Allows Unauthorized Object Access
CVE-2026-16908
8.5 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
Directory traversal
IBM i 7.67.3 Local Auth File Ownership Change via Path Validation
CVE-2026-16898
7.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
External Control of File Name or Path
IBM i 7.6-7.3 TOCTOU File Access Race (CVE-2026-16896)
CVE-2026-16896
7.1 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.
TOCTTOU
IBM i 7.6 OOB Write Remote DoS
CVE-2026-16887
7.5 - High
- August 13, 2026
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Memory Corruption
IBM i OOB Read: Remote Authenticated Info Disclosure 7.6/7.5/7.4/7.3
CVE-2026-16878
5.4 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.x Heap Buffer Overflow Allows Remote Authenticated Info Disclosure
CVE-2026-16871
4.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.
Memory Corruption
IBM i 7.x Uninit Mem during ASN.1 Length Processing: Remote DoS
CVE-2026-16868
8.1 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
Use of Uninitialized Resource
IBM i 7.x NTLM Auth Bypass Remote Privilege Elevation
CVE-2026-16867
8.1 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
authentification
IBM i 7.6-7.3 DoS via Out-of-Bounds Read (CVE-2026-16861)
CVE-2026-16861
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.67.3 OOB Read Info Disclosure
CVE-2026-16859
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
Out-of-Bounds Read in IBM i 7.6-7.3 Enables Remote Info Disclosure
CVE-2026-16853
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
IBM i <=7.6 Stack Buffer Overflow DoS & Info Leak
CVE-2026-16815
8.6 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
Memory Corruption
IBM i 7.6-7.3 Authenticated Privilege Escalation via Improper Privilege Mgmt
CVE-2026-16722
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.
Improper Privilege Management
IBM i 7.6-7.3 Re-auth DoS via Stack Buffer Overflow
CVE-2026-16692
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
Memory Corruption