IBM SECURITY ADVISORY First Issued: Fri Aug 14 20:25:19 CDT 2026 The most recent version of this document is available here: https://aix.software.ibm.com/aix/efixes/security/aix_vios_advisory.asc Security Bulletin: Vulnerabilities in IBM AIX and PowerVM VIOS =============================================================================== SUMMARY: IBM is providing security updates for supported AIX and VIOS releases that are under active fix support. Delivered through Service Packs (SPs) and Fix Packs (FPs), these updates remediate vulnerabilities affecting operating system, virtualization, and third-party components as described in the vulnerability details section. To simplify deployment and maintenance, the security fixes have been incorporated into cumulative maintenance packages. IBM strongly recommends that customers remain on supported releases and promptly apply all applicable security updates and fixes. =============================================================================== VULNERABILITY DETAILS: CVEID: CVE-2026-41254 https://www.cve.org/CVERecord?id=CVE-2026-41254 DESCRIPTION: Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-47057 https://www.cve.org/CVERecord?id=CVE-2026-47057 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-47063 https://www.cve.org/CVERecord?id=CVE-2026-47063 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) CVEID: CVE-2026-47058 https://www.cve.org/CVERecord?id=CVE-2026-47058 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. CVSS Base Score: 7.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) CVEID: CVE-2026-60147 https://www.cve.org/CVERecord?id=CVE-2026-60147 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-46968 https://www.cve.org/CVERecord?id=CVE-2026-46968 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. CVSS Base Score: 5.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) CVEID: CVE-2026-47027 https://www.cve.org/CVERecord?id=CVE-2026-47027 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-47021 https://www.cve.org/CVERecord?id=CVE-2026-47021 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-47059 https://www.cve.org/CVERecord?id=CVE-2026-47059 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. CVSS Base Score: 3.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-47010 https://www.cve.org/CVERecord?id=CVE-2026-47010 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE. CVSS Base Score: 3.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N) CVEID: CVE-2026-8400 https://www.cve.org/CVERecord?id=CVE-2026-8400 DESCRIPTION: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16439 https://www.cve.org/CVERecord?id=CVE-2026-16439 DESCRIPTION: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. CVSS Base Score: 9.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) CVEID: CVE-2026-16441 https://www.cve.org/CVERecord?id=CVE-2026-16441 DESCRIPTION: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method. CVSS Base Score: 6.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N/E:X/CR:X /IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/A U:X/R:X/V:X/RE:X/U:X) CVEID: CVE-2026-16243 https://www.cve.org/CVERecord?id=CVE-2026-16243 DESCRIPTION: In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-2003 https://www.cve.org/CVERecord?id=CVE-2026-2003 DESCRIPTION: Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. CVSS Base Score: 4.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-2004 https://www.cve.org/CVERecord?id=CVE-2026-2004 DESCRIPTION: Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-2005 https://www.cve.org/CVERecord?id=CVE-2026-2005 DESCRIPTION: Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-2006 https://www.cve.org/CVERecord?id=CVE-2026-2006 DESCRIPTION: Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-48959 https://www.cve.org/CVERecord?id=CVE-2026-48959 DESCRIPTION: IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip-new($zip, Name = $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16922 https://www.cve.org/CVERecord?id=CVE-2026-16922 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a time-of- check to time-of-use (TOCTOU) race condition. CVSS Base Score: 7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17424 https://www.cve.org/CVERecord?id=CVE-2026-17424 DESCRIPTION: AIX could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory. CVSS Base Score: 4.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-18828 https://www.cve.org/CVERecord?id=CVE-2026-18828 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a stack- based buffer overflow. CVSS Base Score: 5.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L) CVEID: CVE-2026-17142 https://www.cve.org/CVERecord?id=CVE-2026-17142 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper authentication. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17024 https://www.cve.org/CVERecord?id=CVE-2026-17024 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper certificate validation. CVSS Base Score: 7.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H) CVEID: CVE-2026-19448 https://www.cve.org/CVERecord?id=CVE-2026-19448 DESCRIPTION: A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H) CVEID: CVE-2026-19437 https://www.cve.org/CVERecord?id=CVE-2026-19437 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16875 https://www.cve.org/CVERecord?id=CVE-2026-16875 DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to shell metacharacter injection. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16932 https://www.cve.org/CVERecord?id=CVE-2026-16932 DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16945 https://www.cve.org/CVERecord?id=CVE-2026-16945 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a stack- based buffer overflow. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15061 https://www.cve.org/CVERecord?id=CVE-2026-15061 DESCRIPTION: AIX's nimesis registration service could allow a remote attacker to overwrite files due to path traversal. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L) CVEID: CVE-2026-16847 https://www.cve.org/CVERecord?id=CVE-2026-16847 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17436 https://www.cve.org/CVERecord?id=CVE-2026-17436 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap- based buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-18822 https://www.cve.org/CVERecord?id=CVE-2026-18822 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records. CVSS Base Score: 4.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-17006 https://www.cve.org/CVERecord?id=CVE-2026-17006 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSS Base Score: 8.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-18842 https://www.cve.org/CVERecord?id=CVE-2026-18842 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to an out-of- bounds write. CVSS Base Score: 8.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16831 https://www.cve.org/CVERecord?id=CVE-2026-16831 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16829 https://www.cve.org/CVERecord?id=CVE-2026-16829 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16937 https://www.cve.org/CVERecord?id=CVE-2026-16937 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-18824 https://www.cve.org/CVERecord?id=CVE-2026-18824 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 8.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H) CVEID: CVE-2026-17152 https://www.cve.org/CVERecord?id=CVE-2026-17152 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16886 https://www.cve.org/CVERecord?id=CVE-2026-16886 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out- of-bounds write. CVSS Base Score: 4.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-16972 https://www.cve.org/CVERecord?id=CVE-2026-16972 DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to improper authentication. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L) CVEID: CVE-2026-16934 https://www.cve.org/CVERecord?id=CVE-2026-16934 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a heap- based buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-17040 https://www.cve.org/CVERecord?id=CVE-2026-17040 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2025-12817 https://www.cve.org/CVERecord?id=CVE-2025-12817 DESCRIPTION: Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected. CVSS Base Score: 3.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-16873 https://www.cve.org/CVERecord?id=CVE-2026-16873 DESCRIPTION: AIX could allow a local attacker to achieve local privilege escalation due to an out-of-bounds write. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17121 https://www.cve.org/CVERecord?id=CVE-2026-17121 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled recursion. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16656 https://www.cve.org/CVERecord?id=CVE-2026-16656 DESCRIPTION: IBM AIX could allow a remote attacker to gain root privileges due to improper authentication. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16865 https://www.cve.org/CVERecord?id=CVE-2026-16865 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to command injection. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17118 https://www.cve.org/CVERecord?id=CVE-2026-17118 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a use- after-free vulnerability. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17423 https://www.cve.org/CVERecord?id=CVE-2026-17423 DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read. CVSS Base Score: 7.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) CVEID: CVE-2026-16839 https://www.cve.org/CVERecord?id=CVE-2026-16839 DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser. CVSS Base Score: 9.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H) CVEID: CVE-2026-16866 https://www.cve.org/CVERecord?id=CVE-2026-16866 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out- of-bounds read. CVSS Base Score: 4.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L) CVEID: CVE-2026-16825 https://www.cve.org/CVERecord?id=CVE-2026-16825 DESCRIPTION: AIX could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write. CVSS Base Score: 4.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L) CVEID: CVE-2026-16996 https://www.cve.org/CVERecord?id=CVE-2026-16996 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an integer underflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16935 https://www.cve.org/CVERecord?id=CVE-2026-16935 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a time-of- check to time-of-use (TOCTOU) race condition. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16946 https://www.cve.org/CVERecord?id=CVE-2026-16946 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a heap buffer overflow. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15068 https://www.cve.org/CVERecord?id=CVE-2026-15068 DESCRIPTION: AIX NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 9.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16885 https://www.cve.org/CVERecord?id=CVE-2026-16885 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16958 https://www.cve.org/CVERecord?id=CVE-2026-16958 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out- of-bounds write. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-59995 https://www.cve.org/CVERecord?id=CVE-2026-59995 DESCRIPTION: sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker- controlled server. CVSS Base Score: 5.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L) CVEID: CVE-2026-59996 https://www.cve.org/CVERecord?id=CVE-2026-59996 DESCRIPTION: scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. CVSS Base Score: 5.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L) CVEID: CVE-2026-59997 https://www.cve.org/CVERecord?id=CVE-2026-59997 DESCRIPTION: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. CVSS Base Score: 5.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) CVEID: CVE-2026-59999 https://www.cve.org/CVERecord?id=CVE-2026-59999 DESCRIPTION: In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) CVEID: CVE-2026-60000 https://www.cve.org/CVERecord?id=CVE-2026-60000 DESCRIPTION: sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-60001 https://www.cve.org/CVERecord?id=CVE-2026-60001 DESCRIPTION: sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L) CVEID: CVE-2026-60002 https://www.cve.org/CVERecord?id=CVE-2026-60002 DESCRIPTION: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) CVSS Base Score: 9.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L) CVEID: CVE-2026-16819 https://www.cve.org/CVERecord?id=CVE-2026-16819 DESCRIPTION: AIX could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition. CVSS Base Score: 7.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) CVEID: CVE-2026-6472 https://www.cve.org/CVERecord?id=CVE-2026-6472 DESCRIPTION: Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search\_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 5.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-6473 https://www.cve.org/CVERecord?id=CVE-2026-6473 DESCRIPTION: Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-6474 https://www.cve.org/CVERecord?id=CVE-2026-6474 DESCRIPTION: Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 4.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-6475 https://www.cve.org/CVERecord?id=CVE-2026-6475 DESCRIPTION: Symlink following in PostgreSQL pg\_basebackup plain format and in pg\_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared\_preload\_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-6477 https://www.cve.org/CVERecord?id=CVE-2026-6477 DESCRIPTION: Use of inherently dangerous function PQfn(..., result\_is\_int=0, ...) in PostgreSQL libpq lo\_export(), lo\_read(), lo\_lseek64(), and lo\_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result\_is\_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo\_export command in psql and pg\_dump call lo\_read(), the server superuser can overwrite pg\_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-6478 https://www.cve.org/CVERecord?id=CVE-2026-6478 DESCRIPTION: Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-6637 https://www.cve.org/CVERecord?id=CVE-2026-6637 DESCRIPTION: Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user- controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16852 https://www.cve.org/CVERecord?id=CVE-2026-16852 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer overflow. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-17157 https://www.cve.org/CVERecord?id=CVE-2026-17157 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16874 https://www.cve.org/CVERecord?id=CVE-2026-16874 DESCRIPTION: AIX could allow a local attacker to obtain root privileges due to improper enforcement of RBAC authentication roles. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16894 https://www.cve.org/CVERecord?id=CVE-2026-16894 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16888 https://www.cve.org/CVERecord?id=CVE-2026-16888 DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability. CVSS Base Score: 3.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-17120 https://www.cve.org/CVERecord?id=CVE-2026-17120 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a buffer overflow. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-17160 https://www.cve.org/CVERecord?id=CVE-2026-17160 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16890 https://www.cve.org/CVERecord?id=CVE-2026-16890 DESCRIPTION: AIX could allow a local attacker to obtain sensitive information or cause a denial of service due to an integer overflow. CVSS Base Score: 3.6 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L) CVEID: CVE-2026-16903 https://www.cve.org/CVERecord?id=CVE-2026-16903 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write. CVSS Base Score: 9.6 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-17060 https://www.cve.org/CVERecord?id=CVE-2026-17060 DESCRIPTION: AIX could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) CVEID: CVE-2026-16857 https://www.cve.org/CVERecord?id=CVE-2026-16857 DESCRIPTION: AIX could allow a remote attacker to manipulate network traffic and DNS configuration due to improper authentication. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L) CVEID: CVE-2026-17122 https://www.cve.org/CVERecord?id=CVE-2026-17122 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack- based buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16936 https://www.cve.org/CVERecord?id=CVE-2026-16936 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16827 https://www.cve.org/CVERecord?id=CVE-2026-16827 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer. CVSS Base Score: 5.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-19446 https://www.cve.org/CVERecord?id=CVE-2026-19446 DESCRIPTION: AIX allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16919 https://www.cve.org/CVERecord?id=CVE-2026-16919 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16872 https://www.cve.org/CVERecord?id=CVE-2026-16872 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack- based buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16951 https://www.cve.org/CVERecord?id=CVE-2026-16951 DESCRIPTION: AIX could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. CVSS Base Score: 6.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16924 https://www.cve.org/CVERecord?id=CVE-2026-16924 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16833 https://www.cve.org/CVERecord?id=CVE-2026-16833 DESCRIPTION: AIX could allow a remote attacker to disclose kernel memory due to an out-of- bounds read. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-16973 https://www.cve.org/CVERecord?id=CVE-2026-16973 DESCRIPTION: AIX could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read. CVSS Base Score: 5.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) CVEID: CVE-2026-16838 https://www.cve.org/CVERecord?id=CVE-2026-16838 DESCRIPTION: AIX could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition. CVSS Base Score: 7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17165 https://www.cve.org/CVERecord?id=CVE-2026-17165 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16913 https://www.cve.org/CVERecord?id=CVE-2026-16913 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15078 https://www.cve.org/CVERecord?id=CVE-2026-15078 DESCRIPTION: AIX NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) CVEID: CVE-2026-19449 https://www.cve.org/CVERecord?id=CVE-2026-19449 DESCRIPTION: AIX has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-18716 https://www.cve.org/CVERecord?id=CVE-2026-18716 DESCRIPTION: AIX could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. CVSS Base Score: 7.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H) CVEID: CVE-2026-16909 https://www.cve.org/CVERecord?id=CVE-2026-16909 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an off-by- one error in bounds checking. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17000 https://www.cve.org/CVERecord?id=CVE-2026-17000 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper authentication. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16927 https://www.cve.org/CVERecord?id=CVE-2026-16927 DESCRIPTION: AIX could allow a local attacker to gain root privileges due to a time-of- check to time-of-use (TOCTOU) race condition. CVSS Base Score: 7.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16849 https://www.cve.org/CVERecord?id=CVE-2026-16849 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an improper check for an array index boundary. CVSS Base Score: 4.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-8829 https://www.cve.org/CVERecord?id=CVE-2026-8829 DESCRIPTION: HTML::Entities versions before 3.84 for Perl read freed heap memory in \_decode\_entities. The XS routine backing HTML::Entities::\_decode\_entities cached a pointer (repl) into the entity-value SV returned by hv\_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow\_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl\_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) CVEID: CVE-2026-16917 https://www.cve.org/CVERecord?id=CVE-2026-16917 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an integer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16911 https://www.cve.org/CVERecord?id=CVE-2026-16911 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16837 https://www.cve.org/CVERecord?id=CVE-2026-16837 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16944 https://www.cve.org/CVERecord?id=CVE-2026-16944 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a stack- based buffer overflow. CVSS Base Score: 6.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17124 https://www.cve.org/CVERecord?id=CVE-2026-17124 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an out-of- bounds read. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17422 https://www.cve.org/CVERecord?id=CVE-2026-17422 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 9.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16877 https://www.cve.org/CVERecord?id=CVE-2026-16877 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17138 https://www.cve.org/CVERecord?id=CVE-2026-17138 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack- based buffer overflow. CVSS Base Score: 8.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16928 https://www.cve.org/CVERecord?id=CVE-2026-16928 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a heap- based buffer overflow. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16897 https://www.cve.org/CVERecord?id=CVE-2026-16897 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to an out- of-bounds write. CVSS Base Score: 4.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-18832 https://www.cve.org/CVERecord?id=CVE-2026-18832 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap- based buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-15065 https://www.cve.org/CVERecord?id=CVE-2026-15065 DESCRIPTION: IBM AIX NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file. CVSS Base Score: 9.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) CVEID: CVE-2026-14970 https://www.cve.org/CVERecord?id=CVE-2026-14970 DESCRIPTION: IBM AIX NIM server process is crashing during client registration due to buffer overflow. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16869 https://www.cve.org/CVERecord?id=CVE-2026-16869 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17003 https://www.cve.org/CVERecord?id=CVE-2026-17003 DESCRIPTION: AIX could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write. CVSS Base Score: 7.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L) CVEID: CVE-2026-16841 https://www.cve.org/CVERecord?id=CVE-2026-16841 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16925 https://www.cve.org/CVERecord?id=CVE-2026-16925 DESCRIPTION: AIX could allow a local attacker to achieve privilege escalation due to improper authorization. CVSS Base Score: 7.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) CVEID: CVE-2026-17141 https://www.cve.org/CVERecord?id=CVE-2026-17141 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16989 https://www.cve.org/CVERecord?id=CVE-2026-16989 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links. CVSS Base Score: 7.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) CVEID: CVE-2026-17195 https://www.cve.org/CVERecord?id=CVE-2026-17195 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to an out- of-bounds write. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H) CVEID: CVE-2026-17136 https://www.cve.org/CVERecord?id=CVE-2026-17136 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a format string vulnerability. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16686 https://www.cve.org/CVERecord?id=CVE-2026-16686 DESCRIPTION: AIX could allow a remote attacker to access NFS-exported filesystems due to improper authentication. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) CVEID: CVE-2026-16834 https://www.cve.org/CVERecord?id=CVE-2026-16834 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer underflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16991 https://www.cve.org/CVERecord?id=CVE-2026-16991 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper handling of symbolic links. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16840 https://www.cve.org/CVERecord?id=CVE-2026-16840 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an out-of- bounds write. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16822 https://www.cve.org/CVERecord?id=CVE-2026-16822 DESCRIPTION: AIX could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation. CVSS Base Score: 9.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N) CVEID: CVE-2026-16817 https://www.cve.org/CVERecord?id=CVE-2026-16817 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-17168 https://www.cve.org/CVERecord?id=CVE-2026-17168 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. CVSS Base Score: 8.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16848 https://www.cve.org/CVERecord?id=CVE-2026-16848 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17007 https://www.cve.org/CVERecord?id=CVE-2026-17007 DESCRIPTION: AIX could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. CVSS Base Score: 6.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H) CVEID: CVE-2026-16901 https://www.cve.org/CVERecord?id=CVE-2026-16901 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to an out-of- bounds write. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16836 https://www.cve.org/CVERecord?id=CVE-2026-16836 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16846 https://www.cve.org/CVERecord?id=CVE-2026-16846 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a null pointer dereference. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16816 https://www.cve.org/CVERecord?id=CVE-2026-16816 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 9.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-8368 https://www.cve.org/CVERecord?id=CVE-2026-8368 DESCRIPTION: LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy- Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the redirect target, including across scheme, host, or port changes. A redirect to an attacker controlled host therefore discloses the caller's credentials to that host. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) CVEID: CVE-2026-17425 https://www.cve.org/CVERecord?id=CVE-2026-17425 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a stack buffer overflow. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2025-12818 https://www.cve.org/CVERecord?id=CVE-2025-12818 DESCRIPTION: Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected. CVSS Base Score: 5.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16864 https://www.cve.org/CVERecord?id=CVE-2026-16864 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17171 https://www.cve.org/CVERecord?id=CVE-2026-17171 DESCRIPTION: AIX could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16821 https://www.cve.org/CVERecord?id=CVE-2026-16821 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to a format string vulnerability. CVSS Base Score: 7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16943 https://www.cve.org/CVERecord?id=CVE-2026-16943 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-18670 https://www.cve.org/CVERecord?id=CVE-2026-18670 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) CVEID: CVE-2026-17009 https://www.cve.org/CVERecord?id=CVE-2026-17009 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to a NULL pointer dereference. CVSS Base Score: 4.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-18840 https://www.cve.org/CVERecord?id=CVE-2026-18840 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16845 https://www.cve.org/CVERecord?id=CVE-2026-16845 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16844 https://www.cve.org/CVERecord?id=CVE-2026-16844 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16883 https://www.cve.org/CVERecord?id=CVE-2026-16883 DESCRIPTION: AIX could allow a local attacker to obtain sensitive information due to an out-of-bounds read. CVSS Base Score: 5.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) CVEID: CVE-2026-17159 https://www.cve.org/CVERecord?id=CVE-2026-17159 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an integer overflow. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16824 https://www.cve.org/CVERecord?id=CVE-2026-16824 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to unbounded recursion. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16690 https://www.cve.org/CVERecord?id=CVE-2026-16690 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-12087 https://www.cve.org/CVERecord?id=CVE-2026-12087 DESCRIPTION: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack\_ip\_mreq\_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr\_sourceaddr field with a fixed- size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack\_ip\_mreq\_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure. CVSS Base Score: 9.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) CVEID: CVE-2026-16862 https://www.cve.org/CVERecord?id=CVE-2026-16862 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16891 https://www.cve.org/CVERecord?id=CVE-2026-16891 DESCRIPTION: AIX could allow a local attacker to obtain sensitive information due to an out-of-bounds read. CVSS Base Score: 3.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-16851 https://www.cve.org/CVERecord?id=CVE-2026-16851 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to a use- after-free. CVSS Base Score: 7.4 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) CVEID: CVE-2026-18835 https://www.cve.org/CVERecord?id=CVE-2026-18835 DESCRIPTION: AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 9.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16882 https://www.cve.org/CVERecord?id=CVE-2026-16882 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16842 https://www.cve.org/CVERecord?id=CVE-2026-16842 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-19783 https://www.cve.org/CVERecord?id=CVE-2026-19783 DESCRIPTION: IBM AIX could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation. CVSS Base Score: 6.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-19653 https://www.cve.org/CVERecord?id=CVE-2026-19653 DESCRIPTION: PowerVM VIOS could allow a local attacker to cause a denial of service due to improper handling of memory page table configurations. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H) CVEID: CVE-2026-16850 https://www.cve.org/CVERecord?id=CVE-2026-16850 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16997 https://www.cve.org/CVERecord?id=CVE-2026-16997 DESCRIPTION: AIX could allow a local attacker to execute arbitrary commands due to improper privilege management. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVEID: CVE-2026-17145 https://www.cve.org/CVERecord?id=CVE-2026-17145 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to improper privilege management. CVSS Base Score: 9.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-22016 https://www.cve.org/CVERecord?id=CVE-2026-22016 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) CVEID: CVE-2026-22021 https://www.cve.org/CVERecord?id=CVE-2026-22021 DESCRIPTION: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-22013 https://www.cve.org/CVERecord?id=CVE-2026-22013 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. CVSS Base Score: 5.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N) CVEID: CVE-2026-22018 https://www.cve.org/CVERecord?id=CVE-2026-22018 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. CVSS Base Score: 3.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) CVEID: CVE-2026-34268 https://www.cve.org/CVERecord?id=CVE-2026-34268 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. CVSS Base Score: 2.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-22007 https://www.cve.org/CVERecord?id=CVE-2026-22007 DESCRIPTION: Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. CVSS Base Score: 2.9 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) CVEID: CVE-2026-16952 https://www.cve.org/CVERecord?id=CVE-2026-16952 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to uncontrolled resource consumption. CVSS Base Score: 5.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-17170 https://www.cve.org/CVERecord?id=CVE-2026-17170 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper validation of an allocation size. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16818 https://www.cve.org/CVERecord?id=CVE-2026-16818 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16855 https://www.cve.org/CVERecord?id=CVE-2026-16855 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to a heap buffer overflow. CVSS Base Score: 5.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16706 https://www.cve.org/CVERecord?id=CVE-2026-16706 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to an out- of-bounds write. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16703 https://www.cve.org/CVERecord?id=CVE-2026-16703 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management. CVSS Base Score: 7.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-16814 https://www.cve.org/CVERecord?id=CVE-2026-16814 DESCRIPTION: AIX could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSS Base Score: 8.8 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2026-19442 https://www.cve.org/CVERecord?id=CVE-2026-19442 DESCRIPTION: AIX has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel. CVSS Base Score: 8.2 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) CVEID: CVE-2026-16964 https://www.cve.org/CVERecord?id=CVE-2026-16964 DESCRIPTION: AIX could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information. CVSS Base Score: 6.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) CVEID: CVE-2026-16980 https://www.cve.org/CVERecord?id=CVE-2026-16980 DESCRIPTION: AIX could allow a local attacker to cause a denial of service due to improper validation of symbolic links. CVSS Base Score: 6.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H) CVEID: CVE-2026-17163 https://www.cve.org/CVERecord?id=CVE-2026-17163 DESCRIPTION: AIX could allow a remote attacker to cause a denial of service due to improper validation of an array size field. CVSS Base Score: 7.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-16914 https://www.cve.org/CVERecord?id=CVE-2026-16914 DESCRIPTION: AIX could allow a local attacker to execute arbitrary code due to an out-of- bounds write. CVSS Base Score: 6.7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) CVEID: CVE-2025-15649 https://www.cve.org/CVERecord?id=CVE-2025-15649 DESCRIPTION: IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. \_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die. The exception propagates out of IO::Uncompress::Unzip-new($file) where callers expect undef plus $UnzipError. CVSS Base Score: 5.5 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) CVEID: CVE-2026-48962 https://www.cve.org/CVERecord?id=CVE-2026-48962 DESCRIPTION: IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. \_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; \_getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege. CVSS Base Score: 7.3 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) CVEID: CVE-2026-16926 https://www.cve.org/CVERecord?id=CVE-2026-16926 DESCRIPTION: AIX could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input. CVSS Base Score: 9.1 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) CVEID: CVE-2026-16923 https://www.cve.org/CVERecord?id=CVE-2026-16923 DESCRIPTION: AIX could allow a local attacker to gain elevated privileges due to improper privilege management. CVSS Base Score: 7 CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) AFFECTED PRODUCTS AND VERSIONS: AIX 7.2, 7.3 VIOS 4.1 The vulnerabilities in the following filesets are being addressed: key_fileset = aix Fileset Lower Level Upper Level KEY --------------------------------------------------------- bos.mp64 7.2.5.0 7.2.5.212 key_w_fs bos.mp64 7.3.2.0 7.3.2.5 key_w_fs bos.mp64 7.3.3.0 7.3.3.2 key_w_fs bos.mp64 7.3.4.0 7.3.4.1 key_w_fs To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in AIX user's guide. Example: lslpp -L | grep -i bos.mp64 REMEDIATION: A. APARS IBM has assigned the following APARs to this problem: AIX Level APAR Availability SP KEY ----------------------------------------------------- 7.2.5 IJ59566 08/14/2026 SP13 key_w_apar 7.3.2 IJ59565 08/14/2026 SP05 key_w_apar 7.3.3 IJ59564 08/14/2026 SP03 key_w_apar 7.3.4 IJ59563 08/14/2026 SP02 key_w_apar VIOS Level APAR Availability SP KEY ---------------------------------------------------- 4.1.0 IJ59565 08/14/2026 4.1.0.50 key_w_apar 4.1.1 IJ59564 08/14/2026 4.1.1.30 key_w_apar 4.1.2 IJ59563 08/14/2026 4.1.2.20 key_w_apar B. FIXES IBM strongly recommends addressing the vulnerability now. AIX and VIOS fixes are available. An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update may be used to avoid a reboot. The AIX and VIOS fixes can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities. AIX Level Service Pack ------------------------------------------------ AIX 7.3 TL04 SP2 AIX 7.3 TL03 SP3 AIX 7.3 TL02 SP5 AIX 7.2 TL05 SP13 PowerVM VIOS Level Fix Pack -------------------------------------------- VIOS 4.1.2 4.1.2.20 VIOS 4.1.1 4.1.1.30 VIOS 4.1.0 4.1.0.50 Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL. Note: To apply these patches using nimsh secure, special steps must be taken as the protocol between master and client is updated to be more secure. Please read this article: https://www.ibm.com/support/pages/node/7283157 Note: For VIOS 4.1.0 and VIOS 4.1.1, additional steps are required to migrate to the latest Postgres15 after applying the 4.1.1.30 or 4.1.0.50 FPs above. Instructions to do that can be found here: 4.1.0.50 post-update instructions: https://www.ibm.com/support/pages/node/7283819 4.1.1.30 post-update instructions: https://www.ibm.com/support/pages/node/7283823 IBM recommends customers using unsupported product versions to upgrade to a supported, remediated version to address the identified vulnerabilities. WORKAROUNDS AND MITIGATIONS: None. =============================================================================== CONTACT US: Note: Keywords labeled as KEY in this document are used for parsing purposes. If you would like to receive AIX Security Advisories via email, please visit "My Notifications": http://www.ibm.com/support/mynotifications Contact IBM Support for questions related to this announcement: https://ibm.com/support/ For information on how to securely verify AIX security bulletins and fixes: https://www.ibm.com/support/pages/node/6985269 To obtain the OpenSSL public key that can be used to verify the signed advisories and ifixes: Download the key from our web page: https://aix.software.ibm.com/aix/efixes/security/systems_p_os_aix_security_pubkey.txt To verify the AIX/VIOS security bulletin: Published advisory OpenSSL signature file location: https://aix.software.ibm.com/aix/efixes/security/aix_vios_advisory.asc.sig openssl dgst -sha256 -verify [pubkey_file] -signature [advisory_file].sig [advisory_file] Please contact your local IBM AIX support center for any assistance. REFERENCES: Complete CVSS v3 Guide: http://www.first.org/cvss/user-guide On-line Calculator v3: http://www.first.org/cvss/calculator/3.0 AIX 7.3.4 Release Notes: https://www.ibm.com/docs/en/aix/7.3.0?topic=notes-aix-734-release AIX 7.3.3 Release Notes: https://www.ibm.com/docs/en/aix/7.3.0?topic=notes-aix-733-release AIX 7.3.2 Release Notes: https://www.ibm.com/docs/en/aix/7.3.0?topic=notes-aix-732-release AIX 7.2.5 Release Notes: https://www.ibm.com/docs/en/aix/7.2.0?topic=notes-aix-725-release VIOS Release Notes: https://www.ibm.com/docs/en/power11/9043-MRU?topic=environment-virtual-io-server-release-notes For customers using NIM, refer to Network Installation Management Support Document for more information on upgrade sequencing, migration guidance, troubleshooting information, and FAQs. https://www.ibm.com/support/pages/node/7283157 RELATED INFORMATION: IBM Secure Engineering Web Portal: http://www.ibm.com/security/secure-engineering/bulletins.html IBM Product Security Incident Response Blog: https://www.ibm.com/blogs/psirt/ Security Bulletin: Vulnerabilities in IBM AIX and PowerVM VIOS https://www.ibm.com/support/pages/node/7283858 https://aix.software.ibm.com/aix/efixes/security/aix_vios_advisory.asc IBM recommends that customers review the security bulletin and release notes, determine whether the vulnerabilities affect their environment, confirm compatibility with their applications and platforms, test updates in a non-production environment, and follow their standard change management process. These Service Packs and Fix Packs mainly provide security updates. Some releases may also include planned maintenance content. Refer to the release notes for more information. These Service Packs and Fix Packs do not affect AIX or VIOS product lifecycle, maintenance, entitlement, or support status. Please contact your local IBM AIX Support Center for any assistance. ACKNOWLEDGEMENTS: CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/). CHANGE HISTORY: First Issued: Fri Aug 14 20:25:19 CDT 2026 =============================================================================== *The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin. Disclaimer According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.