CVE-2026-16909CWE-128

CVE-2026-16909

High · published August 20, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
20.8
In the wild
Unconfirmed
What it is

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00286 · 20.8th percentile
Weakness
CWE-128 · Wrap-around Error
Published
2026-08-20T00:17Z
Affected products (7)
ProductVersionsFixed in
ibm/vios≥ 4.1.0, < 4.1.0.504.1.0.50
ibm/vios≥ 4.1.1.0, < 4.1.1.304.1.1.30
ibm/vios≥ 4.1.2.0, < 4.1.2.204.1.2.20
ibm/aix≥ 7.2.5, ≤ 7.2.5.212
ibm/aix≥ 7.3.2, ≤ 7.3.2.5
ibm/aix≥ 7.3.3, ≤ 7.3.3.2
ibm/aix≥ 7.3.4, ≤ 7.3.4.1
References (1)
EPSS history
Timeline
  • 19 AUG 19:55Z
    Vulnerabilities in IBM AIX and PowerVM VIOS
    cvelistv5