CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM

unknownCVE-2026-16722CVE-2026-16860CVE-2026-16863CVE-2026-16907CVE-2026-16908CVE-2026-16961
IBM has patched vulnerabilities in IBM i operating system versions 7.3, 7.4, 7.5 and 7.6. The vulnerabilities concern multiple aspects of the IBM i operating system, including improper privilege management, unmanaged search path elements, out-of-bounds reads and writes, buffer overflows (both heap and stack-based), SQL injections, path traversal, TOCTOU race conditions with symbolic links, improper validation of environment variables and profile names, and improper neutralization of special elements in OS commands. Attackers with valid authentication can exploit these vulnerabilities to escalate privileges, execute arbitrary code, gain access to sensitive data, compromise system integrity or cause a denial-of-service. The vulnerabilities are present in multiple successive versions of IBM i for which multiple updates have been released. The NCSC's advice is therefore to carefully check whether the version in use falls among the vulnerable versions.

CSIRTS triage

What
Multiple vulnerabilities in IBM i including improper privilege management, buffer overflows, SQL injections, path traversal, and command injection allow authenticated attackers to escalate privileges, execute code, and compromise system integrity.
Who is affected
IBM i systems versions 7.3 through 7.6 with valid user authentication are affected.
Urgency
High; authenticated attackers can escalate privileges and execute arbitrary code with multiple attack vectors.
Action
Apply IBM security updates addressing CVE-2026-16722, CVE-2026-16860, and related CVEs for IBM i versions 7.3–7.6.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch IBM i operating system

Get an email when a new IBM i operating system advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-14
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0301

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-16722coverage & exploitation statusNVD · CVE.org
CVE-2026-16860coverage & exploitation statusNVD · CVE.org
CVE-2026-16863coverage & exploitation statusNVD · CVE.org
CVE-2026-16907coverage & exploitation statusNVD · CVE.org
CVE-2026-16908coverage & exploitation statusNVD · CVE.org
CVE-2026-16961coverage & exploitation statusNVD · CVE.org
CVE-2026-16967coverage & exploitation statusNVD · CVE.org
CVE-2026-16975coverage & exploitation statusNVD · CVE.org
CVE-2026-16987coverage & exploitation statusNVD · CVE.org
CVE-2026-17082coverage & exploitation statusNVD · CVE.org
CVE-2026-17083coverage & exploitation statusNVD · CVE.org
CVE-2026-17218coverage & exploitation statusNVD · CVE.org
CVE-2026-17248coverage & exploitation statusNVD · CVE.org
CVE-2026-17271coverage & exploitation statusNVD · CVE.org
CVE-2026-17272coverage & exploitation statusNVD · CVE.org
CVE-2026-17417coverage & exploitation statusNVD · CVE.org
CVE-2026-17445coverage & exploitation statusNVD · CVE.org
CVE-2026-17642coverage & exploitation statusNVD · CVE.org
CVE-2026-18669coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for IBM i operating

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories