CVE-2026-18148
- EPSS 0.21%
- Veröffentlicht 12.08.2026 19:40:20
- Zuletzt bearbeitet 17.08.2026 17:49:38
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
CVE-2026-17111
- EPSS 0.25%
- Veröffentlicht 12.08.2026 19:37:10
- Zuletzt bearbeitet 17.08.2026 17:51:20
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-17082
- EPSS 0.28%
- Veröffentlicht 12.08.2026 19:36:24
- Zuletzt bearbeitet 17.08.2026 14:32:17
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.
CVE-2026-17083
- EPSS 0.46%
- Veröffentlicht 12.08.2026 19:35:53
- Zuletzt bearbeitet 17.08.2026 14:49:13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CVE-2026-17445
- EPSS 0.24%
- Veröffentlicht 12.08.2026 19:34:16
- Zuletzt bearbeitet 17.08.2026 17:50:32
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
CVE-2026-17417
- EPSS 0.42%
- Veröffentlicht 12.08.2026 19:32:53
- Zuletzt bearbeitet 17.08.2026 17:50:46
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
CVE-2026-16907
- EPSS 0.4%
- Veröffentlicht 12.08.2026 17:36:49
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.
CVE-2026-17248
- EPSS 0.33%
- Veröffentlicht 12.08.2026 17:35:51
- Zuletzt bearbeitet 13.08.2026 16:31:58
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
CVE-2026-17271
- EPSS 0.39%
- Veröffentlicht 12.08.2026 17:35:22
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
CVE-2026-17218
- EPSS 0.55%
- Veröffentlicht 12.08.2026 17:35:04
- Zuletzt bearbeitet 13.08.2026 16:33:11
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.