Junglewise Threat Intelligence

CVE-2026-17436: IBM AIX heap-based buffer overflow in NIM

CVE-2026-17436 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are enterprise operating systems used to run mission-critical business applications. A heap-based buffer overflow vulnerability could allow a remote attacker to execute arbitrary code with system privileges, potentially compromising the entire server and any data or services running on it.

Technical details

A heap-based buffer overflow exists in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, exploitable remotely without authentication. The vulnerability is in the NIM (Network Installation Management) component. An attacker can send a specially crafted network request that triggers the buffer overflow, allowing execution of arbitrary code at the privilege level of the affected service. The vulnerability has a CVSS score of 8.8, indicating high severity with network-based attack vector and no authentication required.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated

References

Related threats