CVE-2026-17262
- EPSS 0.19%
- Veröffentlicht 18.09.2026 19:20:36
- Zuletzt bearbeitet 23.09.2026 04:17:41
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
CVE-2026-19086
- EPSS 0.12%
- Veröffentlicht 14.09.2026 21:17:04
- Zuletzt bearbeitet 16.09.2026 19:24:44
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
CVE-2026-16892
- EPSS 0.27%
- Veröffentlicht 04.09.2026 16:40:21
- Zuletzt bearbeitet 08.09.2026 17:25:26
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
CVE-2026-16941
- EPSS 0.23%
- Veröffentlicht 04.09.2026 16:39:59
- Zuletzt bearbeitet 10.09.2026 21:17:20
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
CVE-2026-17057
- EPSS 0.36%
- Veröffentlicht 04.09.2026 16:39:42
- Zuletzt bearbeitet 08.09.2026 18:17:35
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
CVE-2026-17255
- EPSS 0.19%
- Veröffentlicht 04.09.2026 16:39:08
- Zuletzt bearbeitet 10.09.2026 16:17:08
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.
CVE-2026-18073
- EPSS 0.11%
- Veröffentlicht 04.09.2026 16:28:19
- Zuletzt bearbeitet 08.09.2026 19:44:49
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
CVE-2026-18671
- EPSS 0.21%
- Veröffentlicht 13.08.2026 20:46:00
- Zuletzt bearbeitet 17.08.2026 13:24:48
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temp...
CVE-2026-18249
- EPSS 0.28%
- Veröffentlicht 13.08.2026 20:43:03
- Zuletzt bearbeitet 19.08.2026 16:37:41
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.
CVE-2026-18068
- EPSS 0.22%
- Veröffentlicht 13.08.2026 20:41:41
- Zuletzt bearbeitet 19.08.2026 16:35:50
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.