Powervm Vios IBM Powervm Vios

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Powervm Vios.

By the Year

In 2026 there have been 68 vulnerabilities in IBM Powervm Vios with an average score of 7.8 out of ten.

Year Vulnerabilities Average Score
2026 68 7.83

It may take a day or so for new Powervm Vios vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Powervm Vios Security Vulnerabilities

IBM AIX/PowerVM VIOS 7.27.3 RCE via Pointer Validation
CVE-2026-16919 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.

Object Type Confusion

IBM AIX/PowerVM VIOS RCE via Integer Overflow (CVE-2026-16917)
CVE-2026-16917 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.

Integer Overflow or Wraparound

IBM AIX/PowerVM VIOS 4.1 Local OOB Write Arbitrary Code Exec Before 7.3
CVE-2026-16914 6.7 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

Memory Corruption

Stack Buffer Overflow in IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 -> RCE
CVE-2026-16913 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 stack buffer overflow allows remote exec
CVE-2026-16911 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow.

Stack Overflow

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: RCE via Off-By-One bounds check
CVE-2026-16909 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.

Wrap-around Error

IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 OOB Write RCE/DoS
CVE-2026-16903 9.6 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.

Memory Corruption

Out-of-bounds write in IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 remote code exec
CVE-2026-16901 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16897 4.4 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.

Divide By Zero

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16894 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16891 3.3 - Low - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16890 3.6 - Low - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow.

Integer Overflow or Wraparound

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16886 4.3 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16888 3.7 - Low - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.

Directory traversal

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16885 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Stack Overflow

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16883 5.5 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16882 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16877 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.

Stack Overflow

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16875 7.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16874 7.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges due to improper enforcement of RBAC authentication roles.

Improper Privilege Management

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16873 7.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privilege escalation due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16872 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

Stack Overflow

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16869 7.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.

Untrusted Path

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16866 4.8 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16865 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16864 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16862 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16857 8.2 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication.

authentification

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16855 5.5 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16852 7.5 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.

Integer Overflow or Wraparound

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16851 7.4 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a use-after-free.

Dangling pointer

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16850 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.

Improper Privilege Management

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16849 4.3 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary.

out-of-bounds array index

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16848 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16847 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16846 6.5 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null pointer dereference.

NULL Pointer Dereference

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16845 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16844 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16842 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16841 8.8 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16840 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Memory Corruption

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16839 9.4 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser.

Out-of-bounds Read

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16838 7 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.

TOCTTOU

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16837 7.5 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.

Resource Exhaustion

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16836 7.5 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

Resource Exhaustion

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16834 9.8 - Critical - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.

Integer Overflow or Wraparound

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16833 5.3 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memory due to an out-of-bounds read.

Out-of-bounds Read

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16831 7.5 - High - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

Resource Exhaustion

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16829 5.3 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

NULL Pointer Dereference

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could
CVE-2026-16827 5.9 - Medium - August 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.

Use of Uninitialized Resource

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Powervm Vios or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe