Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-16860: IBM i Remote Code Execution Vulnerability

CVE-2026-16860 · published 22 days ago
Summary

IBM i versions 7.6, 7.5, 7.4, and 7.3 have a security weakness that could allow an attacker to take control of your system remotely. This means an attacker could potentially access and manipulate sensitive data, which is a serious concern for businesses. IBM recommends updating to a fixed version to protect against this vulnerability.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm i 7.6
Original advisory text
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
References
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-427Uncontrolled Search Path Element
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-16860 · MITRE
Monitor software like this
Free during beta