Technology · IBM
IBM i vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 67 vulnerabilities in IBM i: 0 in the last 7 days and 62 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-19280, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 62
- Critical, all time
- 0
- Exploited in the wild
- 0
About IBM i
IBM i is an operating system designed for IBM Power Systems, integrating a database, middleware, and security features.
Latest IBM i vulnerabilities
- CVE-2026-19280: IBM i buffer overflow in PASE processmediumCVSS 5.2EPSS 0.1%
- CVE-2026-19086: IBM i buffer overflow in PASE processlowCVSS 3.3EPSS 0.1%
- CVE-2026-18069: IBM i race condition in file ownership handlingmediumCVSS 6EPSS 0.1%
- CVE-2026-18251: IBM i WebSocket origin validation bypassmediumCVSS 4.3EPSS 0.1%
- CVE-2026-18515: IBM i path traversal in Navigator for imediumCVSS 4.3EPSS 0.3%
- CVE-2026-18151: IBM i Navigator race condition in WebSocket handshakemediumCVSS 4.2EPSS 0.1%
- CVE-2026-18221: IBM i improper authentication validation in DDM/DRDAhighCVSS 8.1EPSS 0.3%
- CVE-2026-18175: IBM i improper authorization in DDM target dispatcherhighCVSS 8.1EPSS 0.2%
- CVE-2026-18078: IBM i integer overflow in Save RestoremediumCVSS 4.3EPSS 0.3%
- CVE-2026-18073: IBM i CL command parameter injection vulnerabilitymediumCVSS 4.4EPSS 0.1%
- CVE-2026-17499: IBM i OS command injection in Debug ServermediumCVSS 4.4EPSS 0.1%
- CVE-2026-17470: IBM i buffer overflow in Line Printer DaemonmediumCVSS 5.3EPSS 0.4%
- CVE-2026-17469: IBM i off-by-one write in Line Printer Daemon queue parsermediumCVSS 5.3EPSS 0.2%
- CVE-2026-17274: IBM i predictable server seed security bypassmediumCVSS 5.4EPSS 0.2%
- CVE-2026-17273: IBM i NULL pointer dereference in Debug ServermediumCVSS 6.5EPSS 0.4%
- CVE-2026-17270: IBM i stack-based buffer overflow in Debug ServermediumCVSS 4.3EPSS 0.2%
- CVE-2026-17259: IBM i stack-based buffer overflow in Debug ServermediumCVSS 4.3EPSS 0.4%
- CVE-2026-17255: IBM i denial of service in ICMPv6 Router Advertisement handlingmediumCVSS 4.3EPSS 0.4%
- CVE-2026-17057: IBM i missing authentication in NFSmediumCVSS 6.5EPSS 0.4%
- CVE-2026-16941: IBM i improper authorization in system message modificationmediumCVSS 4.3EPSS 0.2%
- CVE-2026-16892: IBM i authentication bypass in Network Authentication ServicemediumCVSS 5.4EPSS 0.3%
- CVE-2026-16826: IBM i OS command injection in Debug ServermediumCVSS 5.3EPSS 0.1%
- CVE-2026-16693: IBM i cryptographic weakness in Digital Certificate ManagermediumCVSS 4.4EPSS 0.1%
- CVE-2026-18858: IBM i SSH privilege escalation vulnerability in OpenSSHlowCVSS 3.3EPSS 0.1%
- CVE-2026-18715: IBM i XML external entity injection information disclosuremediumCVSS 6.5EPSS 0.4%
Most severe IBM i vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-18193: IBM i security restriction bypass via improper address validationhighCVSS 8.9EPSS 0.4%
- CVE-2026-17223: IBM i buffer overflow in host servers remote code executionhighCVSS 8.8EPSS 0.8%
- CVE-2026-16975: IBM i heap-based buffer overflow in remote code executionhighCVSS 8.8EPSS 0.8%
- CVE-2026-18683: IBM i privilege escalation in Navigator for ihighCVSS 8.8EPSS 0.7%
- CVE-2026-18847: IBM i credential harvesting via Navigator spoofinghighCVSS 8.8EPSS 0.3%
- CVE-2026-17029: IBM i out-of-bounds write in Java Secure Sockets ExtensionhighCVSS 8.8EPSS 0.2%
- CVE-2026-16987: IBM i LANG environment variable privilege escalation in PASEhighCVSS 8.8EPSS 0.1%
- CVE-2026-18101: IBM i privilege escalation in thread authority managementhighCVSS 8.8EPSS 0.1%
- CVE-2026-7870: IBM i privilege escalation via unqualified library callhighCVSS 8.8
- CVE-2026-16908: IBM i path traversal in SQLhighCVSS 8.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 37 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 18 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/i.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM i vulnerabilities", https://junglewise.ai/threats/technologies/i, 26 September 2026.