Junglewise Threat Intelligence

CVE-2026-17136: IBM AIX and PowerVM VIOS format string vulnerability in NIM

CVE-2026-17136 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are core operating systems used to manage enterprise computing infrastructure and virtual machines. A format string vulnerability in the NIM (Network Installation Management) component could allow a remote attacker to execute arbitrary code with system-level privileges, potentially compromising the entire infrastructure and enabling unauthorized access to sensitive business operations.

Technical details

The vulnerability is a format string flaw in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, likely within the NIM service used for remote system management and patching. Format string vulnerabilities occur when untrusted input is passed directly to a format function without proper validation, allowing attackers to read or write arbitrary memory. This vulnerability is network-accessible and requires no authentication or user interaction; an attacker can craft a malicious request to trigger code execution with the privileges of the NIM process. IBM has released security updates as part of Service Packs and Fix Packs to address this issue.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats