Junglewise Threat Intelligence

CVE-2026-18670: IBM AIX and PowerVM VIOS integer underflow denial of service and information disclosure

CVE-2026-18670 · Severity: high · CVSS 8.2 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an integer underflow vulnerability that allows remote attackers to cause service outages and potentially access sensitive system information. This affects the core operating system and virtualization platform used to manage critical enterprise infrastructure, exposing organizations to operational disruption and data compromise.

Technical details

The vulnerability is an integer underflow flaw in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 that can be exploited remotely without authentication. An attacker can trigger the integer underflow to cause a denial of service condition and potentially disclose sensitive information from memory or data structures. The exact vulnerable component is not specified in the advisory, but the network-accessible attack surface combined with no authentication requirement makes this a significant risk. IBM has released security updates through Service Packs and Fix Packs to remediate the vulnerability.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats