Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Published: 2026-08-13
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds read in the NetServer component of IBM i. A remote authenticated attacker can leverage the flaw to read sensitive information or trigger a denial of service. The weakness is a classic example of buffer boundary errors, which can expose confidential data to the attacker or disrupt service availability.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected, covering all major release lines prior to the July 2026 fix. The specific PTFs that contain the repair are MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3. Systems running these versions without the corresponding updates are at risk.

Risk and Exploitability

The issue carries a CVSS score of 5.4, indicating a medium severity level. No EPSS score is available, but the description specifies that a remote authenticated user is required to exploit the flaw, which limits the attacker pool to those with valid credentials. The vulnerability is not in the CISA KEV catalog, so it is unlikely to be actively targeted yet. Nonetheless, the potential for data leakage or service interruption warrants immediate patching.

Generated by OpenCVE AI on August 13, 2026 at 21:47 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs that address NetServer: use MJ10939 for release 7.6, MJ10938 for 7.5, MJ10937 for 7.4, or MJ10936 for 7.3.
  • If the IBM i version is no longer supported, upgrade to a current, supported release that incorporates the security fix.
  • Restrict or suspend access to the NetServer service until the patch or upgrade is in place to reduce the exposure window.

Generated by OpenCVE AI on August 13, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:28:39.746Z

Reserved: 2026-07-24T20:27:41.320Z

Link: CVE-2026-17226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:42.557

Modified: 2026-08-13T21:17:42.557

Link: CVE-2026-17226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses