Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-16860: IBM i Remote Code Execution Vulnerability
CVE-2026-16860 · published 22 days ago
Summary
IBM i versions 7.6, 7.5, 7.4, and 7.3 have a security weakness that could allow an attacker to take control of your system remotely. This means an attacker could potentially access and manipulate sensitive data, which is a serious concern for businesses. IBM recommends updating to a fixed version to protect against this vulnerability.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | i | 7.6 |
Original advisory text
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
References
- https://www.ibm.com/support/pages/node/7283282 vendor-advisory patch
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-427Uncontrolled Search Path Element
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta