I IBM I

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM I.

By the Year

In 2026 there have been 137 vulnerabilities in IBM I with an average score of 6.8 out of ten. Last year, in 2025 I had 14 security vulnerabilities published. That is, 123 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.31




Year Vulnerabilities Average Score
2026 137 6.76
2025 14 7.06
2024 12 6.37
2023 13 7.48
2022 6 4.83
2021 30 6.10
2020 10 4.63
2019 27 6.00
2018 78 0.00

It may take a day or so for new I vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM I Security Vulnerabilities

IBM i 7.3-7.6 Hardcoded Crypto Constants Remote Disclosure of Sensitive Data
CVE-2026-16693 4.4 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

Use of a Broken or Risky Cryptographic Algorithm

IBM i 7.6/7.5/7.4/7.3 Local Command Injection via Improper Sanitization
CVE-2026-16826 5.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM i 7.67.3 Auth Bypass via ServiceName Matching
CVE-2026-16892 5.4 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

authentification

IBM i 7.6 Remote Auth System Msg Mod via Improper Auth
CVE-2026-16941 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

AuthZ

IBM i 7.6/7.5/7.4/7.3 Remote Auth Bypass Enables DoS & Data Integrity Impact
CVE-2026-17057 6.5 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

Missing Authentication for Critical Function

IBM i (7.6-7.3) Buffer Overflow Enables DoS & Integrity Compromise
CVE-2026-17207 6.5 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.

Memory Corruption

IBM i 7.6-7.3 Remote DoS via ICMPv6 Prefix Length Validation
CVE-2026-17255 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

Memory Corruption

IBM i 7.6 Stack Buffer Overflow Remote DoS
CVE-2026-17259 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

Stack Overflow

IBM i 7.3-7.6 Stack Buffer Overflow Denial of Service
CVE-2026-17270 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow.

Stack Overflow

IBM i 7.6-7.3 NULL Deref DOS Remote Auth
CVE-2026-17273 6.5 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

NULL Pointer Dereference

IBM i 7.6/7.5/7.4/7.3 Security Bypass via Predictable Server Seeds
CVE-2026-17274 5.4 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

Use of Insufficiently Random Values

IBM i 7.6/7.5/7.4/7.3 LPD Queue Name Parser Off-by-One Write Causes DoS
CVE-2026-17469 5.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

Memory Corruption

IBM i OS 7.6/7.5/7.4/7.3 Buffer Overflow DoS
CVE-2026-17470 5.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Memory Corruption

IBM i 7.6 Local Command Injection via Improper OS Command Neutralization
CVE-2026-17499 4.4 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM i 7.x CL Command Param Injection (CVE-2026-18073)
CVE-2026-18073 4.4 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.

Shell injection

IBM i 7.x DOS via Remote Authenticated Integer Overflow
CVE-2026-18078 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.

Integer Overflow or Wraparound

IBM i 7.6-7.3 Memory Leak Remote Authenticated DoS
CVE-2026-18076 4.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.

Memory Leak

IBM i 7.6/7.5/7.4/7.3 Impr Auth in DDM Target Dis Enables Remote DB Tx Manip
CVE-2026-18175 8.1 - High - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

AuthZ

IBM i 7.6/7.5/7.4/7.3 auth param validation flaw
CVE-2026-18221 8.1 - High - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

authentification

IBM i 7.x Memory Corruption via Integer Underflow (Remote Auth.)
CVE-2026-18341 6.3 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

Heap-based Buffer Overflow

IBM i 7.6/7.5 SSH Local Auth Privileged File Disclosure
CVE-2026-18858 3.3 - Low - September 04, 2026

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

Privilege Defined With Unsafe Actions

IBM i 7.6-7.3 PASE Authenticated Process Info Disclosure
CVE-2026-18887 6.5 - Medium - September 04, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.

Information Disclosure

IBM i OOB read causing DoS & data exposure in 7.6/7.5/7.4/7.3 (CVE-2026-17015)
CVE-2026-17015 5.4 - Medium - August 19, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM i v7.6 and below: remote auth can overflow via int underflow
CVE-2026-18102 3.5 - Low - August 19, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.

Heap-based Buffer Overflow

Remote Authenticated Info Disclosure via XML External Entities in IBM i 7.6-7.3
CVE-2026-18715 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.

XXE

IBM i 7.6/7.5/7.4/7.3 NetServer Int Overflow DoS
CVE-2026-18671 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service.

Integer Overflow or Wraparound

IBM i 7.6-7.3 JSSE provider stack overflow via TLS session
CVE-2026-18511 7.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.

Memory Corruption

IBM i 7.x local auth privilege escalation via Navigator for i debugger
CVE-2026-18509 8.2 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.

AuthZ

IBM i 7.6/7.5/7.4/7.3 Exp Lev via Java Ptr Validation Fault
CVE-2026-18249 8.4 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.

Improper Privilege Management

IBM i 7.x CVE-2026-18193: Remote Bypass via Addr Validation
CVE-2026-18193 8.9 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

Improper Privilege Management

IBM i 7.x Thread Authority Swap Local Priv Esc
CVE-2026-18101 8.8 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.

Improper Privilege Management

IBM i 7.6-7.3 Local Arbitrary Code/DoS via Improper Bounds Check
CVE-2026-18086 4.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

Memory Corruption

IBM i 7.x Stack Buffer Overflow Culminates in DoS via Remote Attack
CVE-2026-18077 7.5 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

Memory Corruption

IBM i 7.6/7.5/7.4/7.3 Info Disclosure via Byte-Count Confusion
CVE-2026-18068 4.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.

Information Disclosure

IBM i Off-by-One Bounds Checking DoS in 7.6/7.5/7.4/7.3
CVE-2026-18020 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

Out-of-bounds Read

IBM i OOB Read Vulnerability (CVE-2026-17649)
CVE-2026-17649 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.6-7.3 Remote DoS via OutofBounds Write
CVE-2026-17502 8.6 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

Memory Corruption

IBM i 7.6/7.5/7.4/7.3 Remote DoS via improper buffer write
CVE-2026-17476 4.8 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

Memory Corruption

IBM i 7.6-7.3 Local Privilege Escalation via Improper Privilege Management
CVE-2026-17438 4.4 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.

Improper Privilege Management

IBM i Auth Token Validation Flaw 7.6/7.5/7.4/7.3 Remote Info Disclosure
CVE-2026-17075 6.5 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.

authentification

IBM i Remote DoS via Buffer Overflow (v7.3-7.6)
CVE-2026-17272 8.2 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Memory Corruption

IBM i 7.6: OOB Read Enables Remote Authenticated Info Leakage & DoS
CVE-2026-17226 5.4 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM i (pre-8.0) DRDA LO header integer error leads to DoS
CVE-2026-17216 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers.

Integer Overflow or Wraparound

IBM i OOB Read DoS 7.6, 7.5, 7.4, 7.3
CVE-2026-17212 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM i 7.3-7.6 Auth Bypass RCE & Info Leak
CVE-2026-17101 8.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

authentification

IBM i 7.67.3 Improper Auth Enables Remote Info Disclosure
CVE-2026-17099 7.3 - High - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

authentification

IBM i 7.67.3 Path Traversal Enables Remote Info Disclosure
CVE-2026-17088 4.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

Directory traversal

IBM i 7.x DoS via Resource Exhaustion
CVE-2026-17078 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

Resource Exhaustion

IBM i 7.37.6 Remote DoS via Uninitialized Variable
CVE-2026-17077 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.

Use of Uninitialized Variable

IBM i Pre-7.7 DRDA/DDM Resync Defect Causing Remote DOS
CVE-2026-17076 5.3 - Medium - August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.

Allocation of Resources Without Limits or Throttling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM I or by IBM? Click the Watch button to subscribe.

IBM
Vendor

IBM I
Product

subscribe