CVE-2026-84414
- EPSS 0.09%
- Veröffentlicht 29.09.2026 18:00:05
- Zuletzt bearbeitet 02.10.2026 13:55:31
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
CVE-2026-18869
- EPSS 0.22%
- Veröffentlicht 18.09.2026 19:21:31
- Zuletzt bearbeitet 22.09.2026 19:32:25
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.
CVE-2026-17262
- EPSS 0.19%
- Veröffentlicht 18.09.2026 19:20:36
- Zuletzt bearbeitet 23.09.2026 04:17:41
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
- EPSS 0.13%
- Veröffentlicht 14.09.2026 21:17:04
- Zuletzt bearbeitet 16.09.2026 19:24:44
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.
CVE-2026-19086
- EPSS 0.12%
- Veröffentlicht 14.09.2026 21:17:04
- Zuletzt bearbeitet 16.09.2026 19:24:44
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
CVE-2026-19280
- EPSS 0.12%
- Veröffentlicht 14.09.2026 21:17:04
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
CVE-2026-18065
- EPSS 0.31%
- Veröffentlicht 14.09.2026 19:38:26
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i.
CVE-2026-18251
- EPSS 0.14%
- Veröffentlicht 14.09.2026 19:38:07
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.
CVE-2026-18151
- EPSS 0.14%
- Veröffentlicht 14.09.2026 18:42:30
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
CVE-2026-18515
- EPSS 0.28%
- Veröffentlicht 14.09.2026 18:26:59
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to pl...