Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i NetServer contains an off‑by‑one bounds‑checking error that can be triggered by a remote attacker who can communicate with the NetServer service. The flaw causes the server to read an out‑of‑bounds memory location, resulting in a crash or restart that makes the entire operating system unavailable to users. The impact is limited to availability, with no direct compromise of confidentiality or integrity. The description and behavior indicate a remote attack via the NetServer interface, a scenario that matches CWE‑125.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. The vendor has issued PTFs for each release: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Systems running any of those releases should apply the specific PTF for their version; unsupported releases should be upgraded to a supported release that contains the fix.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited active exploitation. The likely attack vector is remote via the NetServer interface, requiring network access to the service. The consequence is a loss of availability that could disrupt business operations if the IBM i system is a core platform.

Generated by OpenCVE AI on August 13, 2026 at 22:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the IBM i PTF that matches the release: MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, or MJ10936 for 7.3. The patch fixes the off‑by‑one bounds‑checking error (CWE‑125) and restores the reliability of NetServer.
  • Limit NetServer access to a whitelist of trusted IP addresses or enforce firewall rules that block unauthorized traffic, thereby reducing the exposure window while the patch is applied.
  • If the environment is running an unsupported IBM i release, upgrade to the latest supported release that contains the fix, eliminating the vulnerability and ensuring ongoing support for future security updates.

Generated by OpenCVE AI on August 13, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T18:07:32.621Z

Reserved: 2026-07-27T23:56:18.399Z

Link: CVE-2026-18020

cve-icon Vulnrichment

Updated: 2026-08-14T17:41:30.885Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T21:17:43.933

Modified: 2026-08-19T16:35:38.813

Link: CVE-2026-18020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T23:00:06Z

Weaknesses