Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-16656: IBM AIX and PowerVM VIOS Authentication Bypass
CVE-2026-16656 · published 1 month ago
Summary
IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 have a security issue where an attacker can access sensitive areas without permission. This could lead to unauthorized access and potentially allow an attacker to gain control of the system. IBM has not released a specific fix for this issue, but recommends applying the latest security patches.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | aix |
7.2 >= 7.2.5, <= 7.2.5.212 >= 7.3.2, <= 7.3.2.5 >= 7.3.3, <= 7.3.3.2 >= 7.3.4, <= 7.3.4.1 |
| ibm | powervm vios | 4.1 |
| ibm | vios |
>= 4.1.0, < 4.1.0.50 >= 4.1.1.0, < 4.1.1.30 >= 4.1.2.0, < 4.1.2.20 cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:* |
Original advisory text
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published19 Aug 2026
Updated27 Sep 2026
First seen19 Aug 2026
Track software like this
Free during beta