Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.
Published: 2026-08-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i Versions 7.6, 7.5, 7.4, and 7.3 contain a heap buffer overflow within NetServer that can be triggered by a remote attacker who is already authenticated. The flaw can lead to the disclosure of sensitive information. It is classified as a buffer overflow (CWE‑787).

Affected Systems

Affected products are IBM i releases 7.6, 7.5, 7.4, and 7.3. For each release the IBM i NetServer PTF that addresses the heap buffer overflow is MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3, all available from IBM's support site.

Risk and Exploitability

The CVSS score of 4.3 indicates a low-level vulnerability in of overall impact and exploitability. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently widely exploited. However, because the attack requires authentication, a compromised or privileged user could obtain sensitive data. The primary attack vector is remote authenticated access to NetServer services.

Generated by OpenCVE AI on August 13, 2026 at 21:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i NetServer PTFs for your specific release (e.g., MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, MJ10936 for 7.3).
  • Upgrade to a supported and fixed IBM i version if you are running an unsupported release.
  • Restrict remote access to NetServer services to trusted networks or specific users to mitigate the risk of unauthorized data disclosure until a patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T18:08:28.962Z

Reserved: 2026-07-24T04:26:21.195Z

Link: CVE-2026-16871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T20:17:16.013

Modified: 2026-08-17T15:42:43.767

Link: CVE-2026-16871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses