Junglewise Threat Intelligence

CVE-2026-18511: IBM i stack-based buffer overflow in JSSE provider

CVE-2026-18511 · Severity: high · CVSS 7.3 · Published 2026-08-13

Executive brief

IBM i is a server operating system used to run critical business applications. A flaw in its Java Secure Sockets Extension (JSSE) component allows a local attacker with valid credentials to crash the Java process or execute arbitrary code by sending specially crafted TLS session data. This could disrupt operations, compromise data, or provide a foothold for further attacks.

Technical details

This vulnerability is a stack-based buffer overflow (CWE-787: Out-of-bounds Write) in the Native IBM i JSSE provider caused by improper bounds checking during TLS session establishment. The attack requires local access and valid authentication credentials. An attacker can overflow a fixed-length buffer on the stack to either execute arbitrary code with the privileges of the JVM process or cause a denial of service by crashing the process. IBM has released PTF patches for affected versions 7.3, 7.4, 7.5, and 7.6 of IBM i Release 5770-JV1.

Affected products

  • IBM IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTF patches available for IBM i 7.3, 7.4, 7.5, 7.6

References

Related threats