Junglewise Threat Intelligence

CVE-2026-17152: IBM AIX and PowerVM VIOS buffer overflow remote code execution

CVE-2026-17152 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are operating systems used to run enterprise workloads and critical business applications. A buffer overflow vulnerability allows a remote attacker without authentication to execute arbitrary code with system privileges, potentially compromising all data and operations on affected servers.

Technical details

CVE-2026-17152 is a buffer overflow vulnerability in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that permits unauthenticated remote code execution. The vulnerability is reachable over the network without requiring authentication or user interaction, making it immediately exploitable. An attacker can leverage this flaw to achieve complete system compromise with elevated privileges. IBM has released security patches through Service Packs and Fix Packs as described in their security bulletin; customers should promptly apply available updates to affected releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with installation instructions

References

Related threats