Executive brief
IBM AIX and PowerVM VIOS are critical operating systems and hypervisor software used to run enterprise workloads. A vulnerability in the Network Installation Manager (NIM) component exposes intermediate certificate authority private keys in publicly available update files, allowing attackers to bypass authentication controls and potentially execute arbitrary code remotely without requiring valid credentials.
Technical details
The vulnerability (CVE-2026-15065) resides in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 NIM, where intermediate certificate authority private keys are stored in cleartext within publicly accessible update files. This allows an attacker to obtain these keys and use them to bypass security restrictions. The exposure results from improper handling of sensitive cryptographic material during the update process. An attacker with network access can retrieve the exposed keys without authentication, then leverage them to hijack or forge trusted communications. IBM has released security updates incorporating fixes into cumulative maintenance packages, which should be applied promptly to all affected systems.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed