CVE-2026-16894 – IBM AIX

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“This patch set closes a wide range of paths to root access, arbitrary code execution, data exposure, and service disruption.”

IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1 are affected by a large set of Critical and High-severity vulnerabilities spanning remote code execution, command injection, authentication bypass, privilege escalation, arbitrary file writes, certificate-validation failures, memory corruption, information disclosure, and denial of service. Several Critical issues carry CVSS scores from 9.1 through 9.9, including remote paths to arbitrary code execution and root privileges. The High-severity issues range from CVSS 7.0 through 8.8 and include additional code execution, privilege escalation, authorization bypass, NFS access, network manipulation, file overwrite, and denial-of-service conditions.

The highest-scoring Critical issues are CVE-2026-15068, CVE-2026-16816, and CVE-2026-18835 at 9.9. CVE-2026-16656, CVE-2026-16834, CVE-2026-16840, CVE-2026-16845, CVE-2026-16862, CVE-2026-16864, CVE-2026-16872, CVE-2026-16882, CVE-2026-16885, CVE-2026-16894, CVE-2026-16913, CVE-2026-16917, CVE-2026-16919, CVE-2026-17040, CVE-2026-17118, CVE-2026-17122, CVE-2026-17136, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, and CVE-2026-17160 each have a CVSS score of 9.8, Critical severity. CVE-2026-16903 is 9.6, CVE-2026-16839 is 9.4, CVE-2026-16822 and CVE-2026-17422 are 9.3, and CVE-2026-15065 and CVE-2026-16926 are 9.1, all Critical severity.

The remaining listed vulnerabilities are High severity, with individual CVSS scores between 7.0 and 8.8. They cover remote and local memory corruption, command execution, privilege escalation, authentication and authorization failures, arbitrary file access, certificate validation weaknesses, and denial-of-service conditions across AIX and PowerVM VIOS components.

Key Details

Affected Product
Ibm Vios
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.