CVE-2026-17266
- EPSS 0.43%
- Veröffentlicht 12.08.2026 17:22:24
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-18235
- EPSS 0.3%
- Veröffentlicht 12.08.2026 17:21:40
- Zuletzt bearbeitet 13.08.2026 16:27:27
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
CVE-2026-17268
- EPSS 0.22%
- Veröffentlicht 12.08.2026 17:21:05
- Zuletzt bearbeitet 13.08.2026 16:29:35
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token.
CVE-2026-17276
- EPSS 0.24%
- Veröffentlicht 12.08.2026 17:20:24
- Zuletzt bearbeitet 13.08.2026 16:28:39
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
- EPSS 0.19%
- Veröffentlicht 12.08.2026 17:19:44
- Zuletzt bearbeitet 13.08.2026 16:27:47
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
CVE-2026-18713
- EPSS 0.51%
- Veröffentlicht 12.08.2026 17:19:22
- Zuletzt bearbeitet 13.08.2026 16:28:11
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
CVE-2026-16904
- EPSS 0.52%
- Veröffentlicht 12.08.2026 17:18:20
- Zuletzt bearbeitet 13.08.2026 16:48:10
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.
CVE-2026-18847
- EPSS 0.18%
- Veröffentlicht 12.08.2026 16:59:52
- Zuletzt bearbeitet 17.08.2026 13:58:36
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
CVE-2026-16694
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:59:17
- Zuletzt bearbeitet 17.08.2026 14:27:44
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...
CVE-2026-17094
- EPSS 0.4%
- Veröffentlicht 12.08.2026 16:57:46
- Zuletzt bearbeitet 17.08.2026 14:20:21
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.