VYPR
Vypr IntelligenceAI-generatedSep 4, 2026· 7 CVEs

IBM i OS: Seven Vulnerabilities Disclosed, Including High-Severity Database Flaw

IBM i OS: Seven vulnerabilities disclosed on September 4, 2026, including a high-severity flaw in database transaction handling and multiple medium-severity issues.

Key findings

  • IBM i OS: Seven vulnerabilities disclosed on September 4, 2026, affecting versions 7.3-7.6.
  • High-severity flaw (CVE-2026-18175) allows manipulation of database transactions due to improper authorization.
  • Multiple medium-severity flaws include denial of service, security bypass, and information disclosure.
  • Vulnerabilities impact various components including DDM, LPD, PASE, and SSH services.
  • IBM has released security updates; users should apply patches for affected versions.

On September 4, 2026, IBM disclosed seven vulnerabilities affecting its IBM i operating system. The vulnerabilities, disclosed within a one-hour window, span various components and impact versions 7.3 through 7.6. The disclosures include one high-severity flaw related to database transaction manipulation and six medium-to-low severity issues ranging from denial of service to information disclosure.

Several vulnerabilities center on authorization and authentication weaknesses. CVE-2026-18175, a high-severity flaw, allows a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. This impacts IBM i versions 7.3 through 7.6.

Other vulnerabilities include denial-of-service (DoS) conditions. CVE-2026-18078, a medium-severity flaw, is caused by an integer overflow, potentially allowing a remote authenticated attacker to cause a DoS. Similarly, CVE-2026-17469, another medium-severity issue, involves an off-by-one write in the LPD queue name parser, enabling a local authenticated attacker to cause a DoS.

Further impacting IBM i are vulnerabilities related to message modification and security bypass. CVE-2026-16941, a medium-severity flaw, permits a remote authenticated attacker to modify certain system messages due to improper authorization. CVE-2026-16892, also medium-severity, allows a remote authenticated attacker to bypass security restrictions through improper authentication during service-name matching.

Information disclosure is also a concern across multiple CVEs. CVE-2026-18887, a medium-severity vulnerability, enables an authenticated attacker to obtain sensitive information within PASE, granting access to process information they should not be permitted to access. Lastly, CVE-2026-18858, a low-severity flaw, allows a local authenticated attacker to obtain information from a privileged file when using SSH on IBM i 7.6 and 7.5.

IBM has addressed these vulnerabilities through security updates. Users of IBM i versions 7.3, 7.4, 7.5, and 7.6 are advised to consult IBM's official advisories for specific patch information and recommended actions to mitigate these risks.

This batch of disclosures highlights the importance of maintaining up-to-date systems and applying security patches promptly to protect against potential exploitation of authorization, authentication, and information disclosure flaws within the IBM i environment.

AI-written article. Grounded in 7 CVE records listed below.