Junglewise Threat Intelligence

CVE-2026-17040: IBM AIX and PowerVM VIOS buffer overflow

CVE-2026-17040 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 are enterprise operating systems and virtualization platforms used to run critical business applications. A remote buffer overflow vulnerability in these systems could allow an attacker to execute arbitrary code with system privileges, potentially compromising all applications and data running on affected servers.

Technical details

CVE-2026-17040 is a remote buffer overflow vulnerability in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. The vulnerability allows a network-based attacker to execute arbitrary code without requiring authentication or user interaction. The specific vulnerable component and root cause are not disclosed in the advisory, but the high CVSS score (9.8) indicates the vulnerability is easily exploitable and results in complete system compromise. Patches are available through IBM Service Packs and Fix Packs as part of cumulative maintenance packages.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats