Junglewise Threat Intelligence

CVE-2026-18086: IBM i out-of-bounds write in JSSE

CVE-2026-18086 · Severity: medium · CVSS 4.5 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise server operating system used by large organizations for mission-critical applications. A flaw in the Java Secure Sockets Extension (JSSE) component allows authenticated local attackers to exploit improper bounds checking, potentially executing arbitrary code or crashing the system. This could lead to complete system compromise or service outages.

Technical details

CVE-2026-18086 is an out-of-bounds write vulnerability (CWE-787) in IBM i's Java Secure Sockets Extension (JSSE) caused by improper bounds checking. The vulnerability requires local access and low privileges but does not require user interaction. An authenticated local attacker can exploit this to either execute arbitrary code with elevated system privileges or trigger a denial of service by crashing the JVM process. IBM has released PTF patches for all affected versions (7.3, 7.4, 7.5, 7.6); customers should apply these immediately.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed: IBM Security Bulletin published

References

Related threats