IBM I
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM I.
By the Year
In 2026 there have been 137 vulnerabilities in IBM I with an average score of 6.8 out of ten. Last year, in 2025 I had 14 security vulnerabilities published. That is, 123 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.31
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 137 | 6.76 |
| 2025 | 14 | 7.06 |
| 2024 | 12 | 6.37 |
| 2023 | 13 | 7.48 |
| 2022 | 6 | 4.83 |
| 2021 | 30 | 6.10 |
| 2020 | 10 | 4.63 |
| 2019 | 27 | 6.00 |
| 2018 | 78 | 0.00 |
It may take a day or so for new I vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM I Security Vulnerabilities
IBM i 7.3-7.6 Hardcoded Crypto Constants Remote Disclosure of Sensitive Data
CVE-2026-16693
4.4 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
Use of a Broken or Risky Cryptographic Algorithm
IBM i 7.6/7.5/7.4/7.3 Local Command Injection via Improper Sanitization
CVE-2026-16826
5.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Shell injection
IBM i 7.67.3 Auth Bypass via ServiceName Matching
CVE-2026-16892
5.4 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
authentification
IBM i 7.6 Remote Auth System Msg Mod via Improper Auth
CVE-2026-16941
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
AuthZ
IBM i 7.6/7.5/7.4/7.3 Remote Auth Bypass Enables DoS & Data Integrity Impact
CVE-2026-17057
6.5 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
Missing Authentication for Critical Function
IBM i (7.6-7.3) Buffer Overflow Enables DoS & Integrity Compromise
CVE-2026-17207
6.5 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
Memory Corruption
IBM i 7.6-7.3 Remote DoS via ICMPv6 Prefix Length Validation
CVE-2026-17255
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
Memory Corruption
IBM i 7.6 Stack Buffer Overflow Remote DoS
CVE-2026-17259
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.
Stack Overflow
IBM i 7.3-7.6 Stack Buffer Overflow Denial of Service
CVE-2026-17270
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.
Stack Overflow
IBM i 7.6-7.3 NULL Deref DOS Remote Auth
CVE-2026-17273
6.5 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.
NULL Pointer Dereference
IBM i 7.6/7.5/7.4/7.3 Security Bypass via Predictable Server Seeds
CVE-2026-17274
5.4 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
Use of Insufficiently Random Values
IBM i 7.6/7.5/7.4/7.3 LPD Queue Name Parser Off-by-One Write Causes DoS
CVE-2026-17469
5.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
Memory Corruption
IBM i OS 7.6/7.5/7.4/7.3 Buffer Overflow DoS
CVE-2026-17470
5.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Memory Corruption
IBM i 7.6 Local Command Injection via Improper OS Command Neutralization
CVE-2026-17499
4.4 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Shell injection
IBM i 7.x CL Command Param Injection (CVE-2026-18073)
CVE-2026-18073
4.4 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
Shell injection
IBM i 7.x DOS via Remote Authenticated Integer Overflow
CVE-2026-18078
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.
Integer Overflow or Wraparound
IBM i 7.6-7.3 Memory Leak Remote Authenticated DoS
CVE-2026-18076
4.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
Memory Leak
IBM i 7.6/7.5/7.4/7.3 Impr Auth in DDM Target Dis Enables Remote DB Tx Manip
CVE-2026-18175
8.1 - High
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
AuthZ
IBM i 7.6/7.5/7.4/7.3 auth param validation flaw
CVE-2026-18221
8.1 - High
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
authentification
IBM i 7.x Memory Corruption via Integer Underflow (Remote Auth.)
CVE-2026-18341
6.3 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
Heap-based Buffer Overflow
IBM i 7.6/7.5 SSH Local Auth Privileged File Disclosure
CVE-2026-18858
3.3 - Low
- September 04, 2026
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Privilege Defined With Unsafe Actions
IBM i 7.6-7.3 PASE Authenticated Process Info Disclosure
CVE-2026-18887
6.5 - Medium
- September 04, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
Information Disclosure
IBM i OOB read causing DoS & data exposure in 7.6/7.5/7.4/7.3 (CVE-2026-17015)
CVE-2026-17015
5.4 - Medium
- August 19, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
IBM i v7.6 and below: remote auth can overflow via int underflow
CVE-2026-18102
3.5 - Low
- August 19, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
Heap-based Buffer Overflow
Remote Authenticated Info Disclosure via XML External Entities in IBM i 7.6-7.3
CVE-2026-18715
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.
XXE
IBM i 7.6/7.5/7.4/7.3 NetServer Int Overflow DoS
CVE-2026-18671
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.
Integer Overflow or Wraparound
IBM i 7.6-7.3 JSSE provider stack overflow via TLS session
CVE-2026-18511
7.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
Memory Corruption
IBM i 7.x local auth privilege escalation via Navigator for i debugger
CVE-2026-18509
8.2 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
AuthZ
IBM i 7.6/7.5/7.4/7.3 Exp Lev via Java Ptr Validation Fault
CVE-2026-18249
8.4 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
Improper Privilege Management
IBM i 7.x CVE-2026-18193: Remote Bypass via Addr Validation
CVE-2026-18193
8.9 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
Improper Privilege Management
IBM i 7.x Thread Authority Swap Local Priv Esc
CVE-2026-18101
8.8 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.
Improper Privilege Management
IBM i 7.6-7.3 Local Arbitrary Code/DoS via Improper Bounds Check
CVE-2026-18086
4.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
Memory Corruption
IBM i 7.x Stack Buffer Overflow Culminates in DoS via Remote Attack
CVE-2026-18077
7.5 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.
Memory Corruption
IBM i 7.6/7.5/7.4/7.3 Info Disclosure via Byte-Count Confusion
CVE-2026-18068
4.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
Information Disclosure
IBM i Off-by-One Bounds Checking DoS in 7.6/7.5/7.4/7.3
CVE-2026-18020
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
Out-of-bounds Read
IBM i OOB Read Vulnerability (CVE-2026-17649)
CVE-2026-17649
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.6-7.3 Remote DoS via OutofBounds Write
CVE-2026-17502
8.6 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Memory Corruption
IBM i 7.6/7.5/7.4/7.3 Remote DoS via improper buffer write
CVE-2026-17476
4.8 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Memory Corruption
IBM i 7.6-7.3 Local Privilege Escalation via Improper Privilege Management
CVE-2026-17438
4.4 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
Improper Privilege Management
IBM i Auth Token Validation Flaw 7.6/7.5/7.4/7.3 Remote Info Disclosure
CVE-2026-17075
6.5 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
authentification
IBM i Remote DoS via Buffer Overflow (v7.3-7.6)
CVE-2026-17272
8.2 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
Memory Corruption
IBM i 7.6: OOB Read Enables Remote Authenticated Info Leakage & DoS
CVE-2026-17226
5.4 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Out-of-bounds Read
IBM i (pre-8.0) DRDA LO header integer error leads to DoS
CVE-2026-17216
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.
Integer Overflow or Wraparound
IBM i OOB Read DoS 7.6, 7.5, 7.4, 7.3
CVE-2026-17212
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Out-of-bounds Read
IBM i 7.3-7.6 Auth Bypass RCE & Info Leak
CVE-2026-17101
8.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.
authentification
IBM i 7.67.3 Improper Auth Enables Remote Info Disclosure
CVE-2026-17099
7.3 - High
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
authentification
IBM i 7.67.3 Path Traversal Enables Remote Info Disclosure
CVE-2026-17088
4.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Directory traversal
IBM i 7.x DoS via Resource Exhaustion
CVE-2026-17078
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
Resource Exhaustion
IBM i 7.37.6 Remote DoS via Uninitialized Variable
CVE-2026-17077
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.
Use of Uninitialized Variable
IBM i Pre-7.7 DRDA/DDM Resync Defect Causing Remote DOS
CVE-2026-17076
5.3 - Medium
- August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.
Allocation of Resources Without Limits or Throttling