Skip to content

CVE-2026-17040 CVE-2026-15068 CVE-2026-16816 CVE-2026-18835 CVE-2026-16882 CVE-2026-17142 CVE-2026-16656 CVE-2026-16834 CVE-2026-16840 CVE-2026-16845

IBM AIX and PowerVM VIOS critical vulnerabilities allow remote code execution (CVE-2026-17040, CVE-2026-15068, and eight more)

Critical 9.9 Vendor: IBM Published

IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 have critical vulnerabilities allowing remote unauthenticated code execution, command injection and privilege escalation. IBM has fixed VIOS builds 4.1.0.50, 4.1.1.30 and 4.1.2.20; apply them promptly.

What happened

IBM has published an advisory covering multiple vulnerabilities in IBM AIX 7.2 and 7.3 and IBM PowerVM VIOS 4.1. Several are reachable over the network without authentication and require no user interaction: a buffer overflow can allow arbitrary code execution, out-of-bounds and heap buffer overflows can allow arbitrary code execution, and an improper authentication flaw can allow arbitrary command execution or root privilege gain. The CVSS base scores for the most severe issues are 9.8 or 9.9, with high impact on confidentiality, integrity and availability.

Other issues require a low-privileged authenticated remote user. NIM-related and other command injection flaws allow that user to execute arbitrary OS commands, and an integer underflow can cause a denial of service. The CVE record does not indicate active exploitation or public disclosure.

Who is affected

IBM AIX 7.2 and 7.3; IBM PowerVM VIOS 4.1. AIX is IBM's Unix operating system, and PowerVM VIOS is the virtual I/O server used on Power Systems. These are typically found in enterprise data centres running critical business or virtualisation workloads. If you run virtualised workloads on IBM Power, VIOS 4.1 is likely to be in scope.

What to do now

IBM's advisory does not list workarounds, so patching is the primary action.

  1. Apply the fixed PowerVM VIOS builds: 4.1.0.50, 4.1.1.30 and 4.1.2.20.
  2. For AIX 7.2 and 7.3, the record does not list fixed AIX levels. Contact IBM support to confirm the applicable AIX update before assuming those hosts are covered.
  3. Because several of these vulnerabilities are reachable over the network without credentials, restrict network access to AIX and VIOS management interfaces and NIM services until patching is complete.
  4. After patching, verify with vulnerability scanning that no affected AIX 7.2/7.3 or VIOS 4.1 systems remain reachable from untrusted networks.

How to detect it

The record includes no vendor-issued indicators of compromise. Review network exposure of AIX and VIOS management services and NIM, and investigate unexpected processes, account creation or outbound connections on affected hosts.

Beyond the patch

Beyond applying IBM's fixes, confirm that AIX and VIOS management services are not reachable from untrusted networks. Most of these vulnerabilities are network-reachable without credentials, so an exposed port is the kind of exposure that Virtual CISO Services can help inventory and close. If any affected system was exposed before patching, code execution or privilege escalation activity may appear in endpoint and SIEM telemetry, which Managed Detection & Response is built to detect.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-17040
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-17040
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-15068
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-15068
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16816
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16816
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-18835
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-18835
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16882
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16882
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-17142
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-17142
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16656
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16656
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16834
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16834
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16840
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16840
PowerVM VIOS
4.1No fixed version listed yet
CVE-2026-16845
AIX
7.2
7.3
No fixed version listed yet
CVE-2026-16845
PowerVM VIOS
4.1No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.