CVE-2026-16821CWE-134

CVE-2026-16821

High · published August 29, 2026

CVSS v3.1
7.0
EPSS
0%
Percentile
0.8
In the wild
Unconfirmed
What it is

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00096 · 0.8th percentile
Weakness
CWE-134 · Use of Externally-Controlled Format String
Published
2026-08-29T02:16Z
Affected products (7)
ProductVersionsFixed in
ibm/aix≥ 7.2.5.0, ≤ 7.2.5.212
ibm/aix≥ 7.3.2, ≤ 7.3.2.5
ibm/aix≥ 7.3.3, ≤ 7.3.3.2
ibm/aix≥ 7.3.4, ≤ 7.3.4.1
ibm/vios≥ 4.1.0, < 4.1.0.504.1.0.50
ibm/vios≥ 4.1.1, < 4.1.1.304.1.1.30
ibm/vios≥ 4.1.2.0, < 4.1.2.204.1.2.20
References (1)
EPSS history
Timeline
  • 30 AUG 16:16Z
    EPSS moved — → 0%
    epss
  • 28 AUG 20:43Z
    Vulnerabilities in IBM AIX and PowerVM VIOS
    cvelistv5