Junglewise Threat Intelligence

CVE-2026-18671: IBM i NetServer integer overflow in bounds checking

CVE-2026-18671 · Severity: medium · CVSS 6.5 · Published 2026-08-13

Executive brief

IBM i NetServer is a file-sharing service that allows networked access to IBM i system resources. An authenticated attacker can trigger an integer overflow flaw in request processing that crashes the NetServer service thread, causing a temporary denial of service. Organizations relying on IBM i for business-critical file sharing may experience service interruptions.

Technical details

The vulnerability exists in NetServer's request processing logic where an integer overflow during bounds checking allows an authenticated attacker to force a server thread exception. The flaw is triggered via network-based exploitation (CWE-190: Integer Overflow or Wraparound), and requires prior authentication to exploit. The primary impact is denial of service through temporary service unavailability; no data integrity or confidentiality compromise occurs. IBM has released PTF MJ10939 for version 7.6 and corresponding fixes for versions 7.5, 7.4, and 7.3.

Affected products

  • IBM IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed

References

Related threats