Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary code. The flaw can compromise data confidentiality, integrity, and availability, providing the attacker with unconstrained control over the affected system. The CVSS score of 8.8 reflects a high severity of this issue.

Affected Systems

IBM i 7.6, 7.5, 7.4, and 7.3 are impacted. IBM has supplied specific PTFs to address the flaw: MJ11019 for 7.6, MJ11050 for 7.5, MJ11051 for 7.4, and MJ11052 for 7.3. Users of unsupported versions should upgrade to a supported and fixed release.

Risk and Exploitability

The CVSS score denotes a high severity, but no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation at this time. A probable attack vector involves a remote authenticated interaction with the system, requiring valid credentials to leverage the buffer overflow and run code.

Generated by OpenCVE AI on August 13, 2026 at 21:25 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ11019 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11019 7.5MJ11050 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11050 7.4MJ11051 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11051 7.3MJ11052 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11052 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM PTF corresponding to your IBM i version (e.g., MJ11019 for 7.6, MJ11050 for 7.5, MJ11051 for 7.4, MJ11052 for 7.3).
  • If operating an unsupported IBM i release, upgrade to a supported, fixed version as recommended by IBM.
  • Restrict remote access to the IBM i system to trusted users only and disable unnecessary services until the patch is fully applied.

Generated by OpenCVE AI on August 13, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
Title IBM i is Affected By A Remote Code Execution Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:54:00.358Z

Reserved: 2026-07-24T08:33:15.673Z

Link: CVE-2026-16975

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:17.240

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses