CVE-2026-17040 CVE-2026-15068 CVE-2026-16816 CVE-2026-18835 CVE-2026-16882 CVE-2026-17142 CVE-2026-16656 CVE-2026-16834 CVE-2026-16840 CVE-2026-16845
IBM AIX and PowerVM VIOS critical vulnerabilities allow remote code execution (CVE-2026-17040, CVE-2026-15068, and eight more)
IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 have critical vulnerabilities allowing remote unauthenticated code execution, command injection and privilege escalation. IBM has fixed VIOS builds 4.1.0.50, 4.1.1.30 and 4.1.2.20; apply them promptly.
What happened
IBM has published an advisory covering multiple vulnerabilities in IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1. Several are reachable over the network without authentication and require no user interaction: a buffer overflow can allow arbitrary code execution, out-of-bounds and heap buffer overflows can allow arbitrary code execution, and an improper authentication flaw can allow arbitrary command execution or root privilege gain. The CVSS base scores for the most severe issues are 9.8 or 9.9, with high impact on confidentiality, integrity and availability.
Other issues require a low-privileged authenticated remote user. NIM-related and other command injection flaws allow that user to execute arbitrary OS commands, and an integer underflow can cause a denial of service. The CVE record does not indicate active exploitation or public disclosure.
Who is affected
IBM AIX 7.2 and 7.3; IBM PowerVM VIOS 4.1. AIX is IBM's Unix operating system, and PowerVM VIOS is the virtual I/O server used on Power Systems. These are typically found in enterprise data centres running critical business or virtualisation workloads. If you run virtualised workloads on IBM Power, VIOS 4.1 is likely to be in scope.
What to do now
IBM's advisory does not list workarounds, so patching is the primary action.
- Apply the fixed PowerVM VIOS builds: 4.1.0.50, 4.1.1.30 and 4.1.2.20.
- For AIX 7.2 and 7.3, the record does not list fixed AIX levels. Contact IBM support to confirm the applicable AIX update before assuming those hosts are covered.
- Because several of these vulnerabilities are reachable over the network without credentials, restrict network access to AIX and VIOS management interfaces and NIM services until patching is complete.
- After patching, verify with vulnerability scanning that no affected AIX 7.2/7.3 or VIOS 4.1 systems remain reachable from untrusted networks.
How to detect it
The record includes no vendor-issued indicators of compromise. Review network exposure of AIX and VIOS management services and NIM, and investigate unexpected processes, account creation or outbound connections on affected hosts.
Beyond the patch
Beyond applying IBM's fixes, confirm that AIX and VIOS management services are not reachable from untrusted networks. Most of these vulnerabilities are network-reachable without credentials, so an exposed port is the kind of exposure that Virtual CISO Services can help inventory and close. If any affected system was exposed before patching, code execution or privilege escalation activity may appear in endpoint and SIEM telemetry, which Managed Detection & Response is built to detect.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-17040 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-17040 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-15068 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-15068 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16816 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16816 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-18835 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-18835 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16882 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16882 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-17142 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-17142 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16656 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16656 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16834 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16834 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16840 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16840 PowerVM VIOS | 4.1 | No fixed version listed yet |
| CVE-2026-16845 AIX | 7.2 7.3 | No fixed version listed yet |
| CVE-2026-16845 PowerVM VIOS | 4.1 | No fixed version listed yet |
References
Vendor advisory
CVE
- CVE-2026-17040 — cve.org
- CVE-2026-17040 — NVD
- CVE-2026-15068 — cve.org
- CVE-2026-15068 — NVD
- CVE-2026-16816 — cve.org
- CVE-2026-16816 — NVD
- CVE-2026-18835 — cve.org
- CVE-2026-18835 — NVD
- CVE-2026-16882 — cve.org
- CVE-2026-16882 — NVD
- CVE-2026-17142 — cve.org
- CVE-2026-17142 — NVD
- CVE-2026-16656 — cve.org
- CVE-2026-16656 — NVD
- CVE-2026-16834 — cve.org
- CVE-2026-16834 — NVD
- CVE-2026-16840 — cve.org
- CVE-2026-16840 — NVD
- CVE-2026-16845 — cve.org
- CVE-2026-16845 — NVD