Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic buffer overflow in IBM i releases 7.6, 7.5, 7.4, and 7.3 that allows a remote attacker to execute arbitrary code. This weakness can be triggered through the host server subsystem and also via auxiliary services such as the debug server, telnet, and DRDA/DDM interfaces, potentially giving the attacker full control over the affected systems.

Affected Systems

IBM i 7.6 (Release5770-SS1), 7.5, 7.4, and 7.3 are impacted. The known fix package track numbers (PTFs) include SJ11101, SJ11097, SJ11098, SJ11099, SJ11100 for the host server; SJ10899 for the debug server; SJ11022 for telnet; and SJ10848 for DRDA/DDM.

Risk and Exploitability

The CVSS score of 8.1 classifies this as high severity, and while a current EPSS score is unavailable, the lack of KEV listing does not negate the critical nature of the flaw. Attackers can exploit the buffer overflow remotely without authentication, leading to arbitrary code execution, data theft, and system compromise. No public exploit exists yet, but the high CVSS and the nature of the vulnerability suggest that exploitation probability is significant enough to warrant immediate action.

Generated by OpenCVE AI on August 13, 2026 at 20:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the host server PTFs listed for each affected release (e.g., SJ11101, SJ11097, SJ11098, SJ11099, SJ11100).
  • Apply the PTF for the debug server (SJ10899).
  • Apply the PTFs for telnet (SJ11022) and DRDA/DDM (SJ10848).
  • If running an older unsupported release, upgrade to the latest supported IBM i release that includes these fixes.

Generated by OpenCVE AI on August 13, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:55:41.032Z

Reserved: 2026-07-24T19:28:05.244Z

Link: CVE-2026-17206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:18.780

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:02Z

Weaknesses