IBM i: 25 Vulnerabilities Disclosed Together, Including Critical RCE and Privilege Escalation
IBM i: 25 vulnerabilities disclosed together, including critical RCE and privilege escalation flaws across versions 7.6-7.3.

Key findings
- 25 vulnerabilities disclosed for IBM i (versions 7.6-7.3) in a single batch on August 13, 2026.
- Critical flaws include arbitrary code execution and privilege escalation with CVSS scores up to 8.8.
- Vulnerabilities span memory corruption (buffer overflows, out-of-bounds reads/writes), security bypass, and information disclosure.
- Affected components include NetServer, Navigator for i, JSSE provider, and DRDA.
- IBM has released cumulative updates to address all disclosed security issues.
On August 13, 2026, a significant batch of 25 vulnerabilities was disclosed for IBM i, affecting versions 7.6, 7.5, 7.4, and 7.3. These vulnerabilities, all disclosed within a one-hour window, span a range of severity, with several critical flaws allowing for arbitrary code execution and privilege escalation. The disclosures highlight a broad range of weaknesses within the IBM i operating system, impacting various components and functionalities.
Several vulnerabilities center on memory corruption, including buffer overflows and out-of-bounds read/write errors. CVE-2026-18511, a high-severity stack-based buffer overflow in the Native IBM i JSSE provider, could allow a local authenticated attacker to execute arbitrary code. Similarly, CVE-2026-18846, CVE-2026-17223, and CVE-2026-17206 are high-severity buffer overflow vulnerabilities that could lead to arbitrary code execution or denial of service. CVE-2026-17502 and CVE-2026-17211 describe out-of-bounds write and read vulnerabilities, respectively, also leading to denial of service conditions.
Privilege escalation and security bypass are other key themes within this batch. CVE-2026-18509, a high-severity flaw, allows a local authenticated attacker to escalate privileges via the Navigator for i debugger. CVE-2026-18249 and CVE-2026-17069 are high-severity vulnerabilities that could allow remote authenticated attackers to gain elevated privileges or bypass security restrictions due to improper validation of pointers and anti-CSRF tokens. CVE-2026-18193, another high-severity vulnerability, enables remote attackers to bypass security restrictions by improperly validating user-controlled addresses.
Information disclosure and denial of service vulnerabilities are also present. CVE-2026-18068, a medium-severity flaw, could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion. CVE-2026-17078 and CVE-2026-17076 detail medium-severity vulnerabilities leading to denial of service through resource exhaustion and improper processing of DRDA and DDM resynchronization requests, respectively. CVE-2026-17216 and CVE-2026-17212 are medium-severity flaws related to improper processing of DRDA large-object headers and out-of-bounds reads, both resulting in denial of service.
IBM has released cumulative updates to address these security issues. Users of IBM i versions 7.6, 7.5, 7.4, and 7.3 are strongly advised to apply these updates promptly to mitigate the risks associated with these vulnerabilities. The broad nature of this disclosure, encompassing critical remote code execution and privilege escalation flaws, underscores the importance of maintaining up-to-date systems and applying security patches as soon as they become available.
This extensive batch of vulnerabilities, disclosed on August 13, 2026, presents a significant security challenge for IBM i users. The range of affected components, from JSSE providers to Navigator for i and DRDA, indicates a systemic need for vigilance. The presence of multiple critical vulnerabilities, including those allowing for arbitrary code execution and privilege escalation, necessitates immediate attention from system administrators. Staying informed about IBM's security advisories and applying patches diligently is crucial for protecting sensitive data and maintaining system integrity. The coordinated disclosure of these 25 CVEs highlights the ongoing efforts of security researchers and the importance of a proactive security posture.