NCSC-2026-0321 [1.00] [M/H] Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS
IBM heeft kwetsbaarheden verholpen in AIX en PowerVM VIOS. Ook heeft IBM eerdere kwetsbaarheden in, onder andere, DB2, WebSphere, Oracle producten als Java en GraalVM, PostgreSQL, OpenSSH en Perl verholpen voor de producten geproduceerd voor AIX. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service - Omzeilen van een beveiligingsmaatregel - Uitvoer van willekeurige code (root/admin-rechten) - Uitvoer van willekeurige code (gebruikersrechten) - Toegang tot gevoelige gegevens - Manipulatie van gegevens - Verhogen van privileges
CSIRTS triage
- What
- IBM has fixed multiple vulnerabilities in AIX, PowerVM VIOS, and related products including DB2, WebSphere, Oracle Java, GraalVM, PostgreSQL, OpenSSH, and Perl that allow denial of service, privilege escalation, arbitrary code execution, and information disclosure.
- Who is affected
- Deployments of IBM AIX, PowerVM VIOS, and associated database, application server, and utility software are affected.
- Urgency
- High urgency; vulnerabilities span arbitrary code execution with root/admin privileges, data manipulation, and circumvention of security measures across critical infrastructure products.
- Action
- Apply IBM security updates for AIX and PowerVM VIOS and coordinate updates for dependent products (DB2, WebSphere, Java, GraalVM, PostgreSQL, OpenSSH, Perl) addressing the listed CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0321
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-128170.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-128180.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-156490.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-20030.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-20041.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 66% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-20051.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-20061.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64720.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-64731.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- unknownUSN-8675-2: Perl vulnerabilitiesubuntu
- high[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits IBM (04 septembre 2026)cert-fr-avis
- high[NEW] [high] IBM AIX and VIOS: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownUSN-8684-1: Perl vulnerabilitiesubuntu
- unknownUSN-8675-1: Perl vulnerabilitiesubuntu
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
More from NCSC-NL Advisories
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able2026-09-11
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS2026-09-11
- unknownNCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS2026-09-10