CVE-2026-17485
- EPSS 0.29%
- Veröffentlicht 12.08.2026 21:24:04
- Zuletzt bearbeitet 17.08.2026 15:47:26
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
CVE-2026-18148
- EPSS 0.21%
- Veröffentlicht 12.08.2026 19:40:20
- Zuletzt bearbeitet 17.08.2026 17:49:38
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
CVE-2026-17417
- EPSS 0.42%
- Veröffentlicht 12.08.2026 19:32:53
- Zuletzt bearbeitet 17.08.2026 17:50:46
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
CVE-2026-17248
- EPSS 0.33%
- Veröffentlicht 12.08.2026 17:35:51
- Zuletzt bearbeitet 13.08.2026 16:31:58
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
CVE-2026-18669
- EPSS 0.5%
- Veröffentlicht 12.08.2026 17:32:05
- Zuletzt bearbeitet 13.08.2026 16:28:03
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
CVE-2026-17420
- EPSS 0.28%
- Veröffentlicht 12.08.2026 17:25:50
- Zuletzt bearbeitet 13.08.2026 16:27:13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
CVE-2026-17266
- EPSS 0.43%
- Veröffentlicht 12.08.2026 17:22:24
- Zuletzt bearbeitet 17.08.2026 13:16:51
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-18713
- EPSS 0.51%
- Veröffentlicht 12.08.2026 17:19:22
- Zuletzt bearbeitet 13.08.2026 16:28:11
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
CVE-2026-16904
- EPSS 0.52%
- Veröffentlicht 12.08.2026 17:18:20
- Zuletzt bearbeitet 13.08.2026 16:48:10
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.
CVE-2026-18106
- EPSS 0.37%
- Veröffentlicht 12.08.2026 16:53:28
- Zuletzt bearbeitet 17.08.2026 14:15:27
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.