Junglewise Threat Intelligence

CVE-2026-16821: IBM AIX format string vulnerability in privileged component

CVE-2026-16821 · Severity: high · CVSS 7 · Published 2026-08-28

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a format string vulnerability that allows local users with limited system access to execute code with elevated privileges. An attacker exploiting this flaw could gain administrative control of the system and compromise all data and services running on it.

Technical details

A format string vulnerability exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, where user-controlled input is passed unsafely to a format string function in a privileged system component. This vulnerability requires local access and existing user privileges to exploit. An attacker can craft a malicious input containing format string specifiers to read arbitrary memory, write to arbitrary memory locations, or execute arbitrary code with the privileges of the affected process. Patches are available through IBM service packs and fix packs as documented in IBM's security bulletin.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-28: disclosed

References

Related threats