CVE-2026-18669
- EPSS 0.5%
- Veröffentlicht 12.08.2026 17:32:05
- Zuletzt bearbeitet 13.08.2026 16:28:03
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
CVE-2026-16863
- EPSS 0.34%
- Veröffentlicht 12.08.2026 17:31:02
- Zuletzt bearbeitet 13.08.2026 16:48:26
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
CVE-2026-16860
- EPSS 0.46%
- Veröffentlicht 12.08.2026 17:30:00
- Zuletzt bearbeitet 13.08.2026 16:48:39
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
CVE-2026-16906
- EPSS 0.51%
- Veröffentlicht 12.08.2026 17:29:14
- Zuletzt bearbeitet 13.08.2026 16:48:00
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
CVE-2026-16856
- EPSS 0.34%
- Veröffentlicht 12.08.2026 17:28:41
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
CVE-2026-16931
- EPSS 0.39%
- Veröffentlicht 12.08.2026 17:27:35
- Zuletzt bearbeitet 13.08.2026 16:47:12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.
CVE-2026-17110
- EPSS 0.48%
- Veröffentlicht 12.08.2026 17:26:57
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
CVE-2026-17109
- EPSS 0.32%
- Veröffentlicht 12.08.2026 17:26:20
- Zuletzt bearbeitet 13.08.2026 16:46:49
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due to parameter injection.
CVE-2026-17420
- EPSS 0.28%
- Veröffentlicht 12.08.2026 17:25:50
- Zuletzt bearbeitet 13.08.2026 16:27:13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
CVE-2026-17222
- EPSS 0.25%
- Veröffentlicht 12.08.2026 17:25:28
- Zuletzt bearbeitet 13.08.2026 16:32:57
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.