Junglewise Threat Intelligence

CVE-2026-16964: IBM AIX and PowerVM VIOS cryptographic key exposure

CVE-2026-16964 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a vulnerability that exposes sensitive cryptographic material used to secure network communications. An attacker with network access can intercept encrypted messages and forge replies, potentially compromising the integrity of system updates, administrative communications, and virtualization management traffic.

Technical details

The vulnerability stems from improper storage and exposure of sensitive cryptographic keys (likely intermediate certificate authority private keys based on referenced CVE-2026-15065) in publicly accessible locations or update files. An unauthenticated network attacker can obtain these keys to decrypt network traffic and forge cryptographic signatures, bypassing message authentication and integrity controls. The affected components include the NIM (Network Installation Management) update mechanism in AIX 7.2, 7.3 and VIOS 4.1. With access to the private keys, attackers can spoof administrative communications, intercept configuration updates, or perform man-in-the-middle attacks. IBM has released security fixes as part of Service Packs and Fix Packs for supported releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM Security Bulletin updated with additional installation instructions

References

Related threats