Junglewise Threat Intelligence

CVE-2026-16975: IBM i heap-based buffer overflow in remote code execution

CVE-2026-16975 · Severity: high · CVSS 8.8 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system running on IBM Power Systems that manages business-critical applications and data. A remote authenticated attacker can exploit a heap-based buffer overflow vulnerability to execute arbitrary code with full system privileges, potentially compromising sensitive business data and disrupting critical operations.

Technical details

The vulnerability is a heap-based buffer overflow (CWE-787: Out-of-bounds Write) in IBM i versions 7.3 through 7.6 that allows remote code execution. An authenticated attacker with network access can trigger the overflow to execute arbitrary code with the privileges of the affected process. The attack requires valid credentials but no user interaction. IBM has released platform-specific patches (PTF) for each affected version: MJ11019 (7.6), MJ11050 (7.5), MJ11051 (7.4), and MJ11052 (7.3).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-11: disclosed
  • 2026-08-13: advisory
  • 2026-08-13: patched: PTF updates available for versions 7.3-7.6

References

Related threats