Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read in the IBM i NetServer component can be triggered by a remote attacker, leading to a denial of service. The affected code fails to check array bounds before accessing memory, which is a classic buffer overread weakness identified as CWE‑125. If an attacker succeeds, the NetServer service will crash, causing service interruption for any applications that rely on it.

Affected Systems

IBM i releases 7.3, 7.4 7.5 and 7.6 are impacted. Patches are available as IBM i PTFs: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Users of unsupported or superseded versions should plan to migrate to a supported and fixed release.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS data is published, so the likelihood of exploitation cannot be quantified, but the vulnerability is remotely exploitable via the NetServer interface. The issue is not currently listed in the CISA KEV catalog, and a formal workaround is not offered by IBM. Given the remote nature and the potential for widespread service disruption, administrators should treat it as a moderate‑to‑high risk for environments exposing NetServer to untrusted networks.

Generated by OpenCVE AI on August 13, 2026 at 21:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Technical Fix Package corresponding to your release – MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6 – to patch the NetServer component.
  • If your system runs an unsupported or superseded IBM i version, upgrade to the latest supported release that includes the NetServer fixes.
  • Limit exposure of the NetServer service by configuring firewall rules or access controls so only trusted hosts can reach it while awaiting or in the process of applying the patch.

Generated by OpenCVE AI on August 13, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:50:20.093Z

Reserved: 2026-07-24T03:52:45.297Z

Link: CVE-2026-16861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:15.577

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses