Junglewise Threat Intelligence

CVE-2026-16982: IBM i heap buffer overflow in host servers

CVE-2026-16982 · Severity: high · CVSS 7.5 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise-grade operating system used by organizations to run mission-critical business applications. A heap buffer overflow vulnerability in IBM i's host servers allows remote attackers to cause service outages by sending specially crafted requests, disrupting business operations and availability without requiring authentication.

Technical details

This vulnerability (CVE-2026-16982) is a heap-based buffer overflow (CWE-787) in IBM i host servers caused by improper validation of client-supplied data. A remote, unauthenticated attacker can send malformed requests to affected host servers, triggering an out-of-bounds write condition that crashes the server and causes denial of service. The vulnerability is network-accessible with low attack complexity, requiring no authentication or user interaction. Patches are available as PTFs (SJ11101, SJ11102, SJ11103, SJ11104 for versions 7.6, 7.5, 7.4, and 7.3 respectively).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTFs available: 7.6 (SJ11101, SJ11097), 7.5 (SJ11102, SJ11098), 7.4 (SJ11103, SJ11099), 7.3 (SJ11104, SJ11100)

References

Related threats