Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
Published: 2026-07-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i 7.4, 7.5, 7.6 and 7.3 permit a remote attacker to send a specially crafted TLS handshake that forces the server to downgrade the TLS protocol to a version that the server configuration has disabled. This flaw weakens encryption and can lead to confidentiality compromise or provide a foothold for further attacks that rely on reduced security. The weakness is classified as CWE-757, an algorithm downgrade vulnerability.

Affected Systems

Affects IBM i releases 7.3, 7.4, 7.5, and 7.6. The official remedy is IBM i Release5770-SS1, which incorporates the relevant PTFs for each release. Users running older or unsupported IBM i versions should plan to upgrade to a supported, patched release.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can trigger the downgrade by sending a crafted TLS handshake over the network; no authentication or local privileges are required, so the attack is remote and network‑based. This increases the attack surface for potential confidentiality or integrity violations, depending on how the downgraded protocol is used by clients and services.

Generated by OpenCVE AI on July 30, 2026 at 23:42 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6MJ09141 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ09141 7.5MJ09140 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ09140 7.4MJ09139 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ09139 7.3MJ09138 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ09138 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply IBM i Release5770-SS1, which contains the required PTFs for the affected IBM i releases (e.g., PTF MJ09141 for 7.6, MJ09140 for 7.5, MJ09139 for 7.4, and MJ09138 for 7.3).
  • Verify the server’s TLS configuration enforces the desired protocol versions and disables older, unsupported protocols.
  • Monitor network traffic or deploy IDS/IPS rules to detect TLS downgrade attempts and any associated anomalous connections.

Generated by OpenCVE AI on July 30, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
Title IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
First Time appeared Ibm
Ibm i
Weaknesses CWE-757
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T13:52:49.123Z

Reserved: 2026-03-26T21:14:44.344Z

Link: CVE-2026-4942

cve-icon Vulnrichment

Updated: 2026-07-20T13:52:45.468Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')