Junglewise Threat Intelligence

CVE-2026-16929: IBM i buffer overflow in host servers

CVE-2026-16929 · Severity: medium · CVSS 5.3 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system running business-critical applications and databases on IBM Power Systems hardware. A buffer overflow vulnerability in the host servers component allows authenticated remote attackers to read sensitive information or cause service disruption. This could expose confidential data or disrupt access to critical business systems.

Technical details

CVE-2026-16929 is a buffer overflow (CWE-787: Out-of-bounds Write) in IBM i host servers that allows a remote authenticated attacker to obtain sensitive information. The vulnerability is triggered when improperly validated client data is processed by the host server, and the attacker must have valid credentials to exploit it. The network attack vector means the attacker does not need local access. IBM has released PTF patches (SJ11101/SJ11097 for 7.6, SJ11102/SJ11098 for 7.5, SJ11103/SJ11099 for 7.4, SJ11104/SJ11100 for 7.3) to address this and related host server vulnerabilities.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTF releases available for all affected versions

References

Related threats