Executive brief
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a vulnerability that exposes sensitive cryptographic material used to secure network communications. An attacker with network access can intercept encrypted messages and forge replies, potentially compromising the integrity of system updates, administrative communications, and virtualization management traffic.
Technical details
The vulnerability stems from improper storage and exposure of sensitive cryptographic keys (likely intermediate certificate authority private keys based on referenced CVE-2026-15065) in publicly accessible locations or update files. An unauthenticated network attacker can obtain these keys to decrypt network traffic and forge cryptographic signatures, bypassing message authentication and integrity controls. The affected components include the NIM (Network Installation Management) update mechanism in AIX 7.2, 7.3 and VIOS 4.1. With access to the private keys, attackers can spoof administrative communications, intercept configuration updates, or perform man-in-the-middle attacks. IBM has released security fixes as part of Service Packs and Fix Packs for supported releases.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM Security Bulletin updated with additional installation instructions