Executive brief
IBM i is an enterprise operating system that runs mission-critical business applications. A remote attacker can exploit a buffer overflow vulnerability by sending malformed requests to host servers, causing the affected server to crash and become unavailable. This disrupts business operations and requires manual recovery.
Technical details
CVE-2026-18846 is a buffer overflow vulnerability (CWE-787: Out-of-bounds Write) in IBM i host servers caused by improper validation of client-supplied data. The vulnerability is remotely exploitable over the network without authentication or user interaction required. An attacker can send specially crafted malformed requests to trigger the buffer overflow and cause a denial of service on the affected host server. IBM has released PTFs (program temporary fixes) for all affected versions (7.3, 7.4, 7.5, 7.6) to address this issue.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed