Description
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write in IBM i 7.6 that allows a remote attacker to corrupt memory and trigger a crash. The primary impact is a denial of service that may affect internal servers or services. This weakness corresponds to an imprecise boundary check in the DST/SST subsystem, resulting in an inability to maintain application integrity.

Affected Systems

The affected product is IBM i version 7.6, including 7.6.0 and earlier 7.6 releases. The problem is limited to the mainframe OS component that handles DST/SST operations and is not present in newer supported releases.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is not available, so the exploitation probability is uncertain. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, leveraging the DST/SST protocol through open network interfaces, which modifies internal memory and causes a crash.

Generated by OpenCVE AI on August 13, 2026 at 21:28 UTC.

Remediation

Vendor Solution

IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10909 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10909 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-999 patch to fix the out‑of‑bounds write flaw.
  • If the patch is not applicable, upgrade the system to a supported and fixed version of IBM i.
  • If upgrading is delayed, restrict external access to the DST/SST services or block the relevant ports to limit remote exploitation.

Generated by OpenCVE AI on August 13, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Title IBM i is Affected By A Denial of Service Vulnerability DST/SST []
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:51:34.109Z

Reserved: 2026-07-24T05:02:35.948Z

Link: CVE-2026-16887

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:16.263

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses