Junglewise Threat Intelligence

CVE-2026-17118: IBM AIX and PowerVM VIOS use-after-free remote code execution

CVE-2026-17118 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 are enterprise operating systems and virtualization platforms used in mission-critical business environments. A use-after-free vulnerability allows remote attackers to execute arbitrary code with no authentication required, potentially compromising entire systems and the applications they host.

Technical details

The vulnerability is a use-after-free memory corruption flaw in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 that permits remote code execution. The vulnerability is network-accessible and requires no authentication or user interaction to exploit. An attacker can leverage this flaw to execute arbitrary code in the context of the affected operating system, resulting in full system compromise. Patches are available through IBM Service Packs and Fix Packs as described in IBM's security bulletin.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with installation instructions

References

Related threats