CVE-2026-17069
- EPSS 0.16%
- Veröffentlicht 13.08.2026 19:55:20
- Zuletzt bearbeitet 17.08.2026 15:39:19
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
CVE-2026-17045
- EPSS 0.3%
- Veröffentlicht 13.08.2026 19:54:58
- Zuletzt bearbeitet 17.08.2026 19:16:26
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
CVE-2026-17043
- EPSS 0.35%
- Veröffentlicht 13.08.2026 19:54:43
- Zuletzt bearbeitet 17.08.2026 15:39:44
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
CVE-2026-17029
- EPSS 0.12%
- Veröffentlicht 13.08.2026 19:54:29
- Zuletzt bearbeitet 17.08.2026 15:39:55
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
CVE-2026-16987
- EPSS 0.11%
- Veröffentlicht 13.08.2026 19:54:15
- Zuletzt bearbeitet 17.08.2026 14:42:35
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
CVE-2026-16975
- EPSS 0.53%
- Veröffentlicht 13.08.2026 19:54:00
- Zuletzt bearbeitet 17.08.2026 16:01:33
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
CVE-2026-16967
- EPSS 0.25%
- Veröffentlicht 13.08.2026 19:53:38
- Zuletzt bearbeitet 17.08.2026 15:25:54
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
CVE-2026-16961
- EPSS 0.31%
- Veröffentlicht 13.08.2026 19:53:26
- Zuletzt bearbeitet 17.08.2026 15:41:32
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-16908
- EPSS 0.41%
- Veröffentlicht 13.08.2026 19:52:16
- Zuletzt bearbeitet 17.08.2026 15:43:12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
CVE-2026-16898
- EPSS 0.11%
- Veröffentlicht 13.08.2026 19:52:02
- Zuletzt bearbeitet 17.08.2026 15:07:23
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.