IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: RCE via Off-By-One bounds check
CVE-2026-16909 Published on August 19, 2026
Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
Weakness Type
Wrap-around Error
Wrap around errors occur whenever a value is incremented past the maximum value for its type and therefore "wraps around" to a very small, negative, or undefined value.
Products Associated with CVE-2026-16909
stack.watch emails you whenever new vulnerabilities are published in IBM Aix or IBM Powervm Vios. Just hit a watch button to start following.
Affected Versions
IBM AIX:- Version 7.2 is affected.
- Version 7.3 is affected.
- Version 4.1 is affected.