CVE-2026-18858
- EPSS 0.09%
- Veröffentlicht 04.09.2026 16:17:21
- Zuletzt bearbeitet 08.09.2026 21:37:00
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
CVE-2026-18887
- EPSS 0.28%
- Veröffentlicht 04.09.2026 16:17:21
- Zuletzt bearbeitet 08.09.2026 21:36:35
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
CVE-2026-17015
- EPSS 0.31%
- Veröffentlicht 19.08.2026 20:34:07
- Zuletzt bearbeitet 24.08.2026 19:35:08
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
CVE-2026-18102
- EPSS 0.22%
- Veröffentlicht 19.08.2026 20:32:50
- Zuletzt bearbeitet 24.08.2026 19:34:30
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
CVE-2026-18715
- EPSS 0.25%
- Veröffentlicht 13.08.2026 20:46:29
- Zuletzt bearbeitet 17.08.2026 13:20:03
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.
CVE-2026-18671
- EPSS 0.21%
- Veröffentlicht 13.08.2026 20:46:00
- Zuletzt bearbeitet 17.08.2026 13:24:48
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temp...
CVE-2026-18511
- EPSS 0.17%
- Veröffentlicht 13.08.2026 20:43:37
- Zuletzt bearbeitet 17.08.2026 13:25:20
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow ...
CVE-2026-18509
- EPSS 0.16%
- Veröffentlicht 13.08.2026 20:43:18
- Zuletzt bearbeitet 17.08.2026 13:41:30
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with ele...
CVE-2026-18249
- EPSS 0.28%
- Veröffentlicht 13.08.2026 20:43:03
- Zuletzt bearbeitet 19.08.2026 16:37:41
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
- EPSS 0.32%
- Veröffentlicht 13.08.2026 20:42:46
- Zuletzt bearbeitet 19.08.2026 16:37:03
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.