Junglewise Threat Intelligence

CVE-2026-18840: IBM AIX and PowerVM VIOS code execution via pointer validation

CVE-2026-18840 · Severity: high · CVSS 8.2 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 are operating systems and virtualization platforms used to run critical business workloads on IBM Power Systems. A local attacker can exploit improper validation of an attacker-controlled pointer to execute arbitrary code with the privileges of the affected process, potentially compromising the entire system.

Technical details

This vulnerability stems from improper validation of an attacker-controlled pointer in IBM AIX and PowerVM VIOS, allowing a local attacker to execute arbitrary code. The vulnerability requires local access to the system. By supplying a malformed pointer, an attacker can trigger memory corruption that leads to code execution at the privilege level of the vulnerable process. Patches are expected through IBM service updates and fix packs.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats