I IBM I

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM I.

By the Year

In 2026 there have been 113 vulnerabilities in IBM I with an average score of 7.1 out of ten. Last year, in 2025 I had 14 security vulnerabilities published. That is, 99 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.01.




Year Vulnerabilities Average Score
2026 113 7.07
2025 14 7.06
2024 12 6.37
2023 13 7.48
2022 6 4.83
2021 30 6.10
2020 10 4.63
2019 27 6.00
2018 78 0.00

It may take a day or so for new I vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM I Security Vulnerabilities

Remote Authenticated Info Disclosure via XML External Entities in IBM i 7.6-7.3
CVE-2026-18715 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.

XXE

IBM i 7.6/7.5/7.4/7.3 NetServer Int Overflow DoS
CVE-2026-18671 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.

Integer Overflow or Wraparound

IBM i 7.6-7.3 JSSE provider stack overflow via TLS session
CVE-2026-18511 7.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.

Memory Corruption

IBM i 7.x local auth privilege escalation via Navigator for i debugger
CVE-2026-18509 8.2 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.

AuthZ

IBM i 7.6/7.5/7.4/7.3 Exp Lev via Java Ptr Validation Fault
CVE-2026-18249 8.4 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.

Improper Privilege Management

IBM i 7.x CVE-2026-18193: Remote Bypass via Addr Validation
CVE-2026-18193 8.9 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

Improper Privilege Management

IBM i 7.x Thread Authority Swap Local Priv Esc
CVE-2026-18101 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.

Improper Privilege Management

IBM i 7.6-7.3 Local Arbitrary Code/DoS via Improper Bounds Check
CVE-2026-18086 4.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

Memory Corruption

IBM i 7.x Stack Buffer Overflow Culminates in DoS via Remote Attack
CVE-2026-18077 7.5 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

Memory Corruption

IBM i 7.6/7.5/7.4/7.3 Info Disclosure via Byte-Count Confusion
CVE-2026-18068 4.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.

Information Disclosure

IBM i Off-by-One Bounds Checking DoS in 7.6/7.5/7.4/7.3
CVE-2026-18020 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

Out-of-bounds Read

IBM i OOB Read Vulnerability (CVE-2026-17649)
CVE-2026-17649 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.6-7.3 Remote DoS via OutofBounds Write
CVE-2026-17502 8.6 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

Memory Corruption

IBM i 7.6/7.5/7.4/7.3 Remote DoS via improper buffer write
CVE-2026-17476 4.8 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

Memory Corruption

IBM i 7.6-7.3 Local Privilege Escalation via Improper Privilege Management
CVE-2026-17438 4.4 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.

Improper Privilege Management

IBM i Auth Token Validation Flaw 7.6/7.5/7.4/7.3 Remote Info Disclosure
CVE-2026-17075 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.

authentification

IBM i Remote DoS via Buffer Overflow (v7.3-7.6)
CVE-2026-17272 8.2 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Memory Corruption

IBM i 7.6: OOB Read Enables Remote Authenticated Info Leakage & DoS
CVE-2026-17226 5.4 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM i (pre-8.0) DRDA LO header integer error leads to DoS
CVE-2026-17216 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.

Integer Overflow or Wraparound

IBM i OOB Read DoS 7.6, 7.5, 7.4, 7.3
CVE-2026-17212 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.3-7.6 Auth Bypass RCE & Info Leak
CVE-2026-17101 8.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

authentification

IBM i 7.67.3 Improper Auth Enables Remote Info Disclosure
CVE-2026-17099 7.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

authentification

IBM i 7.67.3 Path Traversal Enables Remote Info Disclosure
CVE-2026-17088 4.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

Directory traversal

IBM i 7.x DoS via Resource Exhaustion
CVE-2026-17078 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

Resource Exhaustion

IBM i 7.37.6 Remote DoS via Uninitialized Variable
CVE-2026-17077 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.

Use of Uninitialized Variable

IBM i Pre-7.7 DRDA/DDM Resync Defect Causing Remote DOS
CVE-2026-17076 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.

Allocation of Resources Without Limits or Throttling

IBM i 7.3-7.6 Authenticated Priv Escalation via Improper Priv Mgmt
CVE-2026-17074 3.1 - Low - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.

Improper Privilege Management

IBM i 7.6/7.5/7.4/7.3 Path Traversal allows Remote Auth File Manipulation
CVE-2026-17071 2.7 - Low - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.

Directory traversal

IBM i 7.67.3 CSRF Token Validation Bypass for Authenticated Attacker
CVE-2026-17069 8.1 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.

Session Riding

IBM i 7.3-7.6 Unauthorized Ops via Improper Session Mgmt
CVE-2026-17045 8.1 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.

Authentication Bypass by Capture-replay

Remote Authenticated Deletion via Path Traversal in IBM i 7.6/7.5/7.4/7.3
CVE-2026-17043 3.8 - Low - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

Directory traversal

IBM i 7.6/7.5/7.4/7.3 Local OOB Write Arbitrary Code Execution
CVE-2026-17029 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

Memory Corruption

IBM i 7.6/7.5/7.4/7.3: Priv Escalation via LANG Env Var
CVE-2026-16987 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.

External Control of File Name or Path

IBM i 7.6-7.3 Heap Buffer Overflow RCE Remote Authenticated
CVE-2026-16975 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

Memory Corruption

IBM i 7.x TOCTOU Symlink Race Allows Unauthorized Access
CVE-2026-16967 8.5 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.

TOCTTOU

IBM i 7.6/7.5/7.4 SQLi Vulnerability
CVE-2026-16961 7.6 - High - August 13, 2026

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

SQL Injection

IBM i 7.6/7.5/7.4/7.3 Remote AuthID Path Traversal Allows Unauthorized Object Access
CVE-2026-16908 8.5 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.

Directory traversal

IBM i 7.67.3 Local Auth File Ownership Change via Path Validation
CVE-2026-16898 7.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.

External Control of File Name or Path

IBM i 7.6-7.3 TOCTOU File Access Race (CVE-2026-16896)
CVE-2026-16896 7.1 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.

TOCTTOU

IBM i 7.6 OOB Write Remote DoS
CVE-2026-16887 7.5 - High - August 13, 2026

IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

Memory Corruption

IBM i OOB Read: Remote Authenticated Info Disclosure 7.6/7.5/7.4/7.3
CVE-2026-16878 5.4 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.x Heap Buffer Overflow Allows Remote Authenticated Info Disclosure
CVE-2026-16871 4.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.

Memory Corruption

IBM i 7.x Uninit Mem during ASN.1 Length Processing: Remote DoS
CVE-2026-16868 8.1 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.

Use of Uninitialized Resource

IBM i 7.x NTLM Auth Bypass Remote Privilege Elevation
CVE-2026-16867 8.1 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.

authentification

IBM i 7.6-7.3 DoS via Out-of-Bounds Read (CVE-2026-16861)
CVE-2026-16861 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.67.3 OOB Read Info Disclosure
CVE-2026-16859 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

Out-of-Bounds Read in IBM i 7.6-7.3 Enables Remote Info Disclosure
CVE-2026-16853 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM i <=7.6 Stack Buffer Overflow DoS & Info Leak
CVE-2026-16815 8.6 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.

Memory Corruption

IBM i 7.6-7.3 Authenticated Privilege Escalation via Improper Privilege Mgmt
CVE-2026-16722 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

Improper Privilege Management

IBM i 7.6-7.3 Re-auth DoS via Stack Buffer Overflow
CVE-2026-16692 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM I or by IBM? Click the Watch button to subscribe.

IBM
Vendor

IBM I
Product

subscribe