NCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM
IBM has patched vulnerabilities in IBM i operating system versions 7.3, 7.4, 7.5 and 7.6. The vulnerabilities concern multiple aspects of the IBM i operating system, including improper privilege management, unmanaged search path elements, out-of-bounds reads and writes, buffer overflows (both heap and stack-based), SQL injections, path traversal, TOCTOU race conditions with symbolic links, improper validation of environment variables and profile names, and improper neutralization of special elements in OS commands. Attackers with valid authentication can exploit these vulnerabilities to escalate privileges, execute arbitrary code, gain access to sensitive data, compromise system integrity or cause a denial-of-service. The vulnerabilities are present in multiple successive versions of IBM i for which multiple updates have been released. The NCSC's advice is therefore to carefully check whether the version in use falls among the vulnerable versions.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM i including improper privilege management, buffer overflows, SQL injections, path traversal, and command injection allow authenticated attackers to escalate privileges, execute code, and compromise system integrity.
- Who is affected
- IBM i systems versions 7.3 through 7.6 with valid user authentication are affected.
- Urgency
- High; authenticated attackers can escalate privileges and execute arbitrary code with multiple attack vectors.
- Action
- Apply IBM security updates addressing CVE-2026-16722, CVE-2026-16860, and related CVEs for IBM i versions 7.3–7.6.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch IBM i operating system
Get an email when a new IBM i operating system advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0301
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-167220.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-168600.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-168630.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169070.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169080.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169610.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169670.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169750.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-169870.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-170820.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] IBM i: Multiple Vulnerabilitiescert-bund
- highCVE-2026-17272: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to…nvd
- highCVE-2026-16987: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to i…nvd
- highCVE-2026-16975: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary …nvd
- highCVE-2026-16967: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized …nvd
- highCVE-2026-16961: IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially …nvd
- highCVE-2026-16908: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized …nvd
- highCVE-2026-16722: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorize…nvd
- highCVE-2026-17642: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary …nvd
- highCVE-2026-17445: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security re…nvd
- highCVE-2026-17417: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary …nvd
- criticalCVE-2026-17083: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a …nvd
Recent advisories for IBM i operating
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-17075: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and…nvd · 2026-08-13
- highCVE-2026-17045: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthoriz…nvd · 2026-08-13
- high[NEW] [high] IBM Operational Decision Manager: Multiple vulnerabilitiescert-bund · 2026-08-13
- highCVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forge…nvd · 2026-08-05
- mediumCVE-2024-40683: IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, …nvd · 2026-07-30
- lowCVE-2026-14971: IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfig…nvd · 2026-07-17
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13
- unknownNCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Edition2026-08-13