Skip to content

Release roundup

IBM AIX week 34 2026: 32 critical flaws include unauthenticated command execution

Critical 9.9 Vendor: IBM 144 CVEs in scope Published

IBM's week 34 2026 release covers 144 AIX CVEs, some also affecting PowerVM VIOS: 32 critical, 79 high. No CVE is in CISA KEV or reported exploited. Unauthenticated command execution and memory-corruption flaws in AIX and VIOS should be patched first on exposed systems.

The release at a glance

IBM's week 34 2026 release covers 144 CVEs, all in AIX. The severity distribution is 32 critical, 79 high, 30 medium and 3 low. None of the CVEs is present in CISA's KEV catalogue, and none is reported as exploited. The most serious items affect AIX 7.2 and 7.3, and several also affect PowerVM VIOS 4.1, so both AIX and VIOS estates require review. The most urgent items are pre-authentication network flaws, which makes exposure the primary decision point. For the highest-profile AIX and VIOS CVEs, IBM's release lists PowerVM VIOS fixed versions vios 4.1.0.50, vios 4.1.1.30 and vios 4.1.2.20; separate AIX fixed versions are not stated, so AIX update levels should be confirmed with IBM before deployment.

What matters most

Both AIX 7.2/7.3 and PowerVM VIOS 4.1 are affected by the most serious issues. The unauthenticated network flaws to review first are CVE-2026-16882, an OS command-injection flaw; CVE-2026-17142 and CVE-2026-16656, improper authentication flaws, the latter allowing root privilege gain; and CVE-2026-16834, an integer underflow that can cause denial of service. Memory-corruption issues requiring no authentication and rated 9.8 are CVE-2026-16840 (out-of-bounds write), CVE-2026-16845 (heap buffer overflow), and the stack buffer overflows CVE-2026-16862, CVE-2026-16864 and CVE-2026-16872. These rank first because they are network-reachable, require no credentials, and have critical ratings. Three further critical command-injection flaws, CVE-2026-15068, CVE-2026-16816 and CVE-2026-18835, affect the same products and carry a CVSS score of 9.9. They require low-privileged authenticated access rather than none, but an OS command-injection flaw on AIX or VIOS remains a serious containment risk if an attacker already has a limited account. The remaining release adds many critical and high AIX items, but IBM does not describe each individually in this summary; proceed by product exposure.

Patch in this order

  1. Patch internet-facing AIX 7.2/7.3 and PowerVM VIOS 4.1 systems first. Prioritise the unauthenticated critical flaws: CVE-2026-16882, CVE-2026-17142, CVE-2026-16656, CVE-2026-16834, CVE-2026-16840, CVE-2026-16845, CVE-2026-16862, CVE-2026-16864 and CVE-2026-16872. For PowerVM VIOS, fixed versions are vios 4.1.0.50, vios 4.1.1.30 and vios 4.1.2.20. Separate AIX fixed versions are not stated, so confirm AIX update levels with IBM before applying fixes. 2. Address the 9.9-rated authenticated OS command-injection flaws next: CVE-2026-15068, CVE-2026-16816 and CVE-2026-18835. They require only low-privileged access, but successful exploitation allows arbitrary OS commands with broad impact. 3. Review the remaining critical and high AIX items. The release contains 32 critical and 79 high CVEs, so group patches by AIX service pack or interim fix and prioritise systems reachable from untrusted networks or shared services. 4. Apply medium and low items through normal change management. Confirm whether individual CVEs are covered by the same AIX update set or require separate fixes, since only PowerVM VIOS fixed versions are listed for the top items.

Beyond the patch

A release this size becomes manageable when the network exposure is known before patch week. Virtual CISO Services helps identify the exposed AIX and VIOS services and open ports that unauthenticated flaws such as CVE-2026-16882 and CVE-2026-17142 would require, while Managed Detection & Response watches for command execution, privilege escalation and anomalous administrative activity. Implementation & Assessment Services can validate that injection and authentication weaknesses are closed on critical builds before they are presented to auditors.

Every CVE in this release

CVEProductSeverity
CVE-2026-15068AIXCritical 9.9Advisory →
CVE-2026-16816AIXCritical 9.9Advisory →
CVE-2026-18835AIXCritical 9.9Advisory →
CVE-2026-16882AIXCritical 9.8Advisory →
CVE-2026-17142AIXCritical 9.8Advisory →
CVE-2026-16656AIXCritical 9.8Advisory →
CVE-2026-16834AIXCritical 9.8Advisory →
CVE-2026-16840AIXCritical 9.8Advisory →
CVE-2026-16845AIXCritical 9.8Advisory →
CVE-2026-16862AIXCritical 9.8
CVE-2026-16864AIXCritical 9.8
CVE-2026-16872AIXCritical 9.8
CVE-2026-16885AIXCritical 9.8
CVE-2026-16894AIXCritical 9.8
CVE-2026-16913AIXCritical 9.8
CVE-2026-16917AIXCritical 9.8
CVE-2026-16919AIXCritical 9.8
CVE-2026-17040AIXCritical 9.8Advisory →
CVE-2026-17118AIXCritical 9.8
CVE-2026-17122AIXCritical 9.8
CVE-2026-17136AIXCritical 9.8
CVE-2026-17141AIXCritical 9.8
CVE-2026-17145AIXCritical 9.8
CVE-2026-17152AIXCritical 9.8
CVE-2026-17157AIXCritical 9.8
CVE-2026-17160AIXCritical 9.8
CVE-2026-16903AIXCritical 9.6
CVE-2026-16839AIXCritical 9.4
CVE-2026-16822AIXCritical 9.3
CVE-2026-17422AIXCritical 9.3
CVE-2026-15065AIXCritical 9.1
CVE-2026-16926AIXCritical 9.1
CVE-2026-16850AIXHigh 8.8
CVE-2026-16842AIXHigh 8.8
CVE-2026-16844AIXHigh 8.8
CVE-2026-16848AIXHigh 8.8
CVE-2026-16865AIXHigh 8.8
CVE-2026-16877AIXHigh 8.8
CVE-2026-16911AIXHigh 8.8
CVE-2026-17436AIXHigh 8.8
Show all 144
CVEProductSeverity
CVE-2026-18832AIXHigh 8.8
CVE-2026-16814AIXHigh 8.8
CVE-2026-16841AIXHigh 8.8
CVE-2026-16847AIXHigh 8.8
CVE-2026-16901AIXHigh 8.8
CVE-2026-16909AIXHigh 8.8
CVE-2026-16932AIXHigh 8.8
CVE-2026-16996AIXHigh 8.8
CVE-2026-16934AIXHigh 8.8
CVE-2026-16936AIXHigh 8.8
CVE-2026-19449AIXHigh 8.8
CVE-2026-17168AIXHigh 8.5
CVE-2026-18824AIXHigh 8.4
CVE-2026-18842AIXHigh 8.4
CVE-2026-17006AIXHigh 8.3
CVE-2026-15061AIXHigh 8.2
CVE-2026-16686AIXHigh 8.2
CVE-2026-16857AIXHigh 8.2
CVE-2026-18670AIXHigh 8.2
CVE-2026-16943AIXHigh 8.2
CVE-2026-18840AIXHigh 8.2
CVE-2026-19442AIXHigh 8.2
CVE-2026-15078AIXHigh 8.1
CVE-2026-17000AIXHigh 8.1
CVE-2026-17060AIXHigh 8.1
CVE-2026-17138AIXHigh 8.1
CVE-2026-19437AIXHigh 8.1
CVE-2026-18716AIXHigh 7.9
CVE-2026-16869AIXHigh 7.8
CVE-2026-16874AIXHigh 7.8
CVE-2026-16875AIXHigh 7.8
CVE-2026-16997AIXHigh 7.8
CVE-2026-17124AIXHigh 7.8
CVE-2026-17171AIXHigh 7.8
CVE-2026-16703AIXHigh 7.8
CVE-2026-16873AIXHigh 7.8
CVE-2026-16935AIXHigh 7.8
CVE-2026-16937AIXHigh 7.8
CVE-2026-16945AIXHigh 7.8
CVE-2026-16946AIXHigh 7.8
CVE-2026-16991AIXHigh 7.8
CVE-2026-17003AIXHigh 7.7
CVE-2026-17024AIXHigh 7.7
CVE-2026-17423AIXHigh 7.7
CVE-2026-16819AIXHigh 7.7
CVE-2026-19446AIXHigh 7.5
CVE-2026-16690AIXHigh 7.5
CVE-2026-16706AIXHigh 7.5
CVE-2026-16817AIXHigh 7.5
CVE-2026-16818AIXHigh 7.5
CVE-2026-16824AIXHigh 7.5
CVE-2026-16831AIXHigh 7.5
CVE-2026-16836AIXHigh 7.5
CVE-2026-16852AIXHigh 7.5
CVE-2026-16924AIXHigh 7.5
CVE-2026-16928AIXHigh 7.5
CVE-2026-17121AIXHigh 7.5
CVE-2026-17159AIXHigh 7.5
CVE-2026-17163AIXHigh 7.5
CVE-2026-17165AIXHigh 7.5
CVE-2026-17170AIXHigh 7.5
CVE-2026-17425AIXHigh 7.5
CVE-2026-14970AIXHigh 7.5
CVE-2026-16837AIXHigh 7.5
CVE-2026-16851AIXHigh 7.4
CVE-2026-16927AIXHigh 7.3
CVE-2026-16925AIXHigh 7.1
CVE-2026-16989AIXHigh 7.1
CVE-2026-16838AIXHigh 7.0
CVE-2026-16922AIXHigh 7.0
CVE-2026-16923AIXHigh 7.0
CVE-2026-16914AIXMedium 6.7
CVE-2026-16951AIXMedium 6.7
CVE-2026-16944AIXMedium 6.7
CVE-2026-17007AIXMedium 6.7
CVE-2026-19783AIXMedium 6.7
CVE-2026-16846AIXMedium 6.5
CVE-2026-16958AIXMedium 6.5
CVE-2026-16964AIXMedium 6.5
CVE-2026-16972AIXMedium 6.5
CVE-2026-19448AIXMedium 6.5
CVE-2026-19653AIXMedium 6.5
CVE-2026-17195AIXMedium 6.5
CVE-2026-16980AIXMedium 6.3
CVE-2026-16827AIXMedium 5.9
CVE-2026-16855AIXMedium 5.5
CVE-2026-16883AIXMedium 5.5
CVE-2026-16952AIXMedium 5.5
CVE-2026-16973AIXMedium 5.5
CVE-2026-18828AIXMedium 5.4
CVE-2026-16829AIXMedium 5.3
CVE-2026-16833AIXMedium 5.3
CVE-2026-17120AIXMedium 5.3
CVE-2026-16866AIXMedium 4.8
CVE-2026-17424AIXMedium 4.8
CVE-2026-17009AIXMedium 4.7
CVE-2026-16897AIXMedium 4.4
CVE-2026-18822AIXMedium 4.4
CVE-2026-16849AIXMedium 4.3
CVE-2026-16886AIXMedium 4.3
CVE-2026-16825AIXMedium 4.2
CVE-2026-16888AIXLow 3.7
CVE-2026-16890AIXLow 3.6
CVE-2026-16891AIXLow 3.3

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.