Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16656: IBM AIX and PowerVM VIOS Authentication Bypass

CVE-2026-16656 · published 1 month ago
Summary

IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 have a security issue where an attacker can access sensitive areas without permission. This could lead to unauthorized access and potentially allow an attacker to gain control of the system. IBM has not released a specific fix for this issue, but recommends applying the latest security patches.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm aix 7.2
>= 7.2.5, <= 7.2.5.212
>= 7.3.2, <= 7.3.2.5
>= 7.3.3, <= 7.3.3.2
>= 7.3.4, <= 7.3.4.1
ibm powervm vios 4.1
ibm vios >= 4.1.0, < 4.1.0.50
>= 4.1.1.0, < 4.1.1.30
>= 4.1.2.0, < 4.1.2.20
cpe:2.3:a:ibm:vios:*:*:*:*:*:*:*:*
Original advisory text
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published19 Aug 2026
Updated27 Sep 2026
First seen19 Aug 2026
Sources
CVE-2026-16656 · MITRE
Track software like this
Free during beta