CVE-2026-16906 – IBM i

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“This update closes multiple paths to code execution, privilege escalation, unauthorized access, and service disruption across IBM i.”

IBM i 7.3 through 7.6 are affected by a broad set of security flaws spanning memory corruption, command execution, authentication and authorization weaknesses, path traversal, SQL injection, information disclosure, and denial of service. The most severe issues are CVE-2026-16860 with a CVSS score of 9.9, Critical severity; CVE-2026-17083 and CVE-2026-17218 at 9.8, Critical severity; and CVE-2026-17276 at 9.6, Critical severity. These vulnerabilities can enable arbitrary code execution or privilege escalation under their respective attack conditions.

The High-severity vulnerabilities range from CVSS 7.1 to 8.9 and include additional arbitrary code and command execution, privilege escalation, authentication bypass, memory corruption, unauthorized object access, SQL injection, and denial-of-service conditions. The remaining Medium and Low issues cover information disclosure, path traversal, authorization weaknesses, memory-safety defects, injection flaws, and service disruption. No exploitation claim is included because the supplied data identifies exploitation as none.

CVE List:

CVE-2026-16860, CVE-2026-17083, CVE-2026-17218, CVE-2026-17276, CVE-2026-16674, CVE-2026-16722, CVE-2026-16815, CVE-2026-16856, CVE-2026-16867, CVE-2026-16868, CVE-2026-16904, CVE-2026-16906, CVE-2026-16908, CVE-2026-16967, CVE-2026-16975, CVE-2026-16987, CVE-2026-17029, CVE-2026-17045, CVE-2026-17069, CVE-2026-17082, CVE-2026-17095, CVE-2026-17101, CVE-2026-17110, CVE-2026-17197, CVE-2026-17206, CVE-2026-17220, CVE-2026-17223, CVE-2026-17272, CVE-2026-17417, CVE-2026-17418, CVE-2026-17445, CVE-2026-17485, CVE-2026-17502, CVE-2026-17642, CVE-2026-18098, CVE-2026-18099, CVE-2026-18101, CVE-2026-18193, CVE-2026-18235, CVE-2026-18249, CVE-2026-18509, CVE-2026-18669, CVE-2026-18683, CVE-2026-18713, CVE-2026-18847, CVE-2026-16863, CVE-2026-16887, CVE-2026-16896, CVE-2026-16898, CVE-2026-16907, CVE-2026-16931, CVE-2026-16961, CVE-2026-16982, CVE-2026-17004, CVE-2026-17099, CVE-2026-17111, CVE-2026-17199, CVE-2026-17229, CVE-2026-17248, CVE-2026-17271, CVE-2026-18071, CVE-2026-18077, CVE-2026-18511, CVE-2026-18846, CVE-2026-16692, CVE-2026-16694, CVE-2026-16853, CVE-2026-17075, CVE-2026-17266, CVE-2026-17268, CVE-2026-17419, CVE-2026-17420, CVE-2026-18250, CVE-2026-18671, CVE-2026-18715, CVE-2026-16859, CVE-2026-16861, CVE-2026-16878, CVE-2026-16929, CVE-2026-17076, CVE-2026-17077, CVE-2026-17078, CVE-2026-17212, CVE-2026-17216, CVE-2026-17226, CVE-2026-17649, CVE-2026-18020, CVE-2026-16871, CVE-2026-17088, CVE-2026-17094, CVE-2026-17109, CVE-2026-17222, CVE-2026-17438, CVE-2026-17476, CVE-2026-18068, CVE-2026-18086, CVE-2026-18106, CVE-2026-18144, CVE-2026-18148, CVE-2026-18150, CVE-2026-17043, CVE-2026-17074, CVE-2026-18246, CVE-2026-17071

Four Critical vulnerabilities create the highest risk, including code execution and privilege escalation.

Multiple High-severity flaws provide additional paths to command execution, elevated privileges, unauthorized access, and service disruption.

The affected scope spans IBM i 7.3 through 7.6, with some vulnerabilities limited to specific releases.

The patch set addresses a broad mix of memory-safety, authentication, authorization, injection, and file-access weaknesses.

Key Details

Affected Product
Ibm I
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.