{"schema_version":1,"title":"IBM i vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 69 vulnerabilities in IBM i: 0 in the last 7 days and 64 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18869, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/i","json_url":"https://junglewise.ai/threats/technologies/i.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/i","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":30,"all_time":69,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":26,"last_90_days":64,"last_365_days":69},"latest":[{"cve":"CVE-2026-18869","cvss":6.4,"epss":0.0022,"slug":"cve-2026-18869-ibm-i-7-6-7-5-7-4-and-7-3-could-allow-a-remote-authenticated","title":"IBM i FTP server-side request forgery in PORT and EPRT commands","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:10.703+00:00","url":"https://junglewise.ai/threats/cve-2026-18869-ibm-i-7-6-7-5-7-4-and-7-3-could-allow-a-remote-authenticated"},{"cve":"CVE-2026-17262","cvss":5.4,"epss":0.0019,"slug":"cve-2026-17262-ibm-i-7-6-7-5-7-4-and-7-3-could-allow-a-local-attacker-to-cause-a","title":"IBM i FTP authentication denial of service","severity":"medium","exploited":false,"published_at":"2026-09-18T20:17:09.933+00:00","url":"https://junglewise.ai/threats/cve-2026-17262-ibm-i-7-6-7-5-7-4-and-7-3-could-allow-a-local-attacker-to-cause-a"},{"cve":"CVE-2026-19280","cvss":5.2,"epss":0.0012,"slug":"cve-2026-19280-ibm-i-buffer-overflow-in-pase-process","title":"IBM i buffer overflow in PASE process","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:04.627+00:00","url":"https://junglewise.ai/threats/cve-2026-19280-ibm-i-buffer-overflow-in-pase-process"},{"cve":"CVE-2026-19086","cvss":3.3,"epss":0.0012,"slug":"cve-2026-19086-ibm-i-buffer-overflow-in-pase-process","title":"IBM i buffer overflow in PASE process","severity":"low","exploited":false,"published_at":"2026-09-14T21:17:04.35+00:00","url":"https://junglewise.ai/threats/cve-2026-19086-ibm-i-buffer-overflow-in-pase-process"},{"cve":"CVE-2026-18069","cvss":6,"epss":0.0013,"slug":"cve-2026-18069-ibm-i-race-condition-in-file-ownership-handling","title":"IBM i race condition in file ownership handling","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:04.217+00:00","url":"https://junglewise.ai/threats/cve-2026-18069-ibm-i-race-condition-in-file-ownership-handling"},{"cve":"CVE-2026-18251","cvss":4.3,"epss":0.0014,"slug":"cve-2026-18251-ibm-i-websocket-origin-validation-bypass","title":"IBM i WebSocket origin validation bypass","severity":"medium","exploited":false,"published_at":"2026-09-14T20:16:42.93+00:00","url":"https://junglewise.ai/threats/cve-2026-18251-ibm-i-websocket-origin-validation-bypass"},{"cve":"CVE-2026-18515","cvss":4.3,"epss":0.0028,"slug":"cve-2026-18515-ibm-i-path-traversal-in-navigator-for-i","title":"IBM i path traversal in Navigator for i","severity":"medium","exploited":false,"published_at":"2026-09-14T19:17:16.407+00:00","url":"https://junglewise.ai/threats/cve-2026-18515-ibm-i-path-traversal-in-navigator-for-i"},{"cve":"CVE-2026-18151","cvss":4.2,"epss":0.0014,"slug":"cve-2026-18151-ibm-i-navigator-race-condition-in-websocket-handshake","title":"IBM i Navigator race condition in WebSocket handshake","severity":"medium","exploited":false,"published_at":"2026-09-14T19:17:15.693+00:00","url":"https://junglewise.ai/threats/cve-2026-18151-ibm-i-navigator-race-condition-in-websocket-handshake"},{"cve":"CVE-2026-18221","cvss":8.1,"epss":0.0034,"slug":"cve-2026-18221-ibm-i-improper-authentication-validation-in-ddm-drda","title":"IBM i improper authentication validation in DDM/DRDA","severity":"high","exploited":false,"published_at":"2026-09-04T17:16:56.15+00:00","url":"https://junglewise.ai/threats/cve-2026-18221-ibm-i-improper-authentication-validation-in-ddm-drda"},{"cve":"CVE-2026-18175","cvss":8.1,"epss":0.002,"slug":"cve-2026-18175-ibm-i-improper-authorization-in-ddm-target-dispatcher","title":"IBM i improper authorization in DDM target dispatcher","severity":"high","exploited":false,"published_at":"2026-09-04T17:16:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-18175-ibm-i-improper-authorization-in-ddm-target-dispatcher"},{"cve":"CVE-2026-18078","cvss":4.3,"epss":0.0029,"slug":"cve-2026-18078-ibm-i-integer-overflow-in-save-restore","title":"IBM i integer overflow in Save Restore","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.883+00:00","url":"https://junglewise.ai/threats/cve-2026-18078-ibm-i-integer-overflow-in-save-restore"},{"cve":"CVE-2026-18073","cvss":4.4,"epss":0.0011,"slug":"cve-2026-18073-ibm-i-cl-command-parameter-injection-vulnerability","title":"IBM i CL command parameter injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.627+00:00","url":"https://junglewise.ai/threats/cve-2026-18073-ibm-i-cl-command-parameter-injection-vulnerability"},{"cve":"CVE-2026-17499","cvss":4.4,"epss":0.0012,"slug":"cve-2026-17499-ibm-i-os-command-injection-in-debug-server","title":"IBM i OS command injection in Debug Server","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:54.937+00:00","url":"https://junglewise.ai/threats/cve-2026-17499-ibm-i-os-command-injection-in-debug-server"},{"cve":"CVE-2026-17470","cvss":5.3,"epss":0.0039,"slug":"cve-2026-17470-ibm-i-buffer-overflow-in-line-printer-daemon","title":"IBM i buffer overflow in Line Printer Daemon","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:54.63+00:00","url":"https://junglewise.ai/threats/cve-2026-17470-ibm-i-buffer-overflow-in-line-printer-daemon"},{"cve":"CVE-2026-17469","cvss":5.3,"epss":0.0021,"slug":"cve-2026-17469-ibm-i-off-by-one-write-in-line-printer-daemon-queue-parser","title":"IBM i off-by-one write in Line Printer Daemon queue parser","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:54.487+00:00","url":"https://junglewise.ai/threats/cve-2026-17469-ibm-i-off-by-one-write-in-line-printer-daemon-queue-parser"},{"cve":"CVE-2026-17274","cvss":5.4,"epss":0.0024,"slug":"cve-2026-17274-ibm-i-predictable-server-seed-security-bypass","title":"IBM i predictable server seed security bypass","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:53.71+00:00","url":"https://junglewise.ai/threats/cve-2026-17274-ibm-i-predictable-server-seed-security-bypass"},{"cve":"CVE-2026-17273","cvss":6.5,"epss":0.0035,"slug":"cve-2026-17273-ibm-i-null-pointer-dereference-in-debug-server","title":"IBM i NULL pointer dereference in Debug Server","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:53.57+00:00","url":"https://junglewise.ai/threats/cve-2026-17273-ibm-i-null-pointer-dereference-in-debug-server"},{"cve":"CVE-2026-17270","cvss":4.3,"epss":0.0021,"slug":"cve-2026-17270-ibm-i-stack-based-buffer-overflow-in-debug-server","title":"IBM i stack-based buffer overflow in Debug Server","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:53.4+00:00","url":"https://junglewise.ai/threats/cve-2026-17270-ibm-i-stack-based-buffer-overflow-in-debug-server"},{"cve":"CVE-2026-17259","cvss":4.3,"epss":0.0036,"slug":"cve-2026-17259-ibm-i-stack-based-buffer-overflow-in-debug-server","title":"IBM i stack-based buffer overflow in Debug Server","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:53.267+00:00","url":"https://junglewise.ai/threats/cve-2026-17259-ibm-i-stack-based-buffer-overflow-in-debug-server"},{"cve":"CVE-2026-17255","cvss":4.3,"epss":0.0041,"slug":"cve-2026-17255-ibm-i-denial-of-service-in-icmpv6-router-advertisement-handling","title":"IBM i denial of service in ICMPv6 Router Advertisement handling","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:53.14+00:00","url":"https://junglewise.ai/threats/cve-2026-17255-ibm-i-denial-of-service-in-icmpv6-router-advertisement-handling"},{"cve":"CVE-2026-17057","cvss":6.5,"epss":0.0038,"slug":"cve-2026-17057-ibm-i-missing-authentication-in-nfs","title":"IBM i missing authentication in NFS","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:52.893+00:00","url":"https://junglewise.ai/threats/cve-2026-17057-ibm-i-missing-authentication-in-nfs"},{"cve":"CVE-2026-16941","cvss":4.3,"epss":0.0023,"slug":"cve-2026-16941-ibm-i-improper-authorization-in-system-message-modification","title":"IBM i improper authorization in system message modification","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:52.77+00:00","url":"https://junglewise.ai/threats/cve-2026-16941-ibm-i-improper-authorization-in-system-message-modification"},{"cve":"CVE-2026-16892","cvss":5.4,"epss":0.0025,"slug":"cve-2026-16892-ibm-i-authentication-bypass-in-network-authentication-service","title":"IBM i authentication bypass in Network Authentication Service","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:52.643+00:00","url":"https://junglewise.ai/threats/cve-2026-16892-ibm-i-authentication-bypass-in-network-authentication-service"},{"cve":"CVE-2026-16826","cvss":5.3,"epss":0.0013,"slug":"cve-2026-16826-ibm-i-os-command-injection-in-debug-server","title":"IBM i OS command injection in Debug Server","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:52.517+00:00","url":"https://junglewise.ai/threats/cve-2026-16826-ibm-i-os-command-injection-in-debug-server"},{"cve":"CVE-2026-16693","cvss":4.4,"epss":0.0013,"slug":"cve-2026-16693-ibm-i-cryptographic-weakness-in-digital-certificate-manager","title":"IBM i cryptographic weakness in Digital Certificate Manager","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:52.39+00:00","url":"https://junglewise.ai/threats/cve-2026-16693-ibm-i-cryptographic-weakness-in-digital-certificate-manager"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":37},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":18},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"},{"name":"IBM Db2","slug":"db2","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/db2"},{"name":"IBM Mq","slug":"mq","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/mq"},{"name":"IBM Verify Identity Access","slug":"verify-identity-access","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/verify-identity-access"},{"name":"IBM Power Systems Firmware","slug":"power-systems-firmware","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/power-systems-firmware"}],"technology":{"hub":true,"name":"IBM i","slug":"i","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":["ibm-i"],"category":"operating-system","homepage":"https://www.ibm.com/it-infrastructure/power/os/ibm-i","description":"IBM i is an operating system designed for IBM Power Systems, integrating a database, middleware, and security features.","url":"https://junglewise.ai/threats/technologies/i"},"most_severe":[{"cve":"CVE-2026-18193","cvss":8.9,"epss":0.0045,"slug":"cve-2026-18193-ibm-i-security-restriction-bypass-via-improper-address-validation","title":"IBM i security restriction bypass via improper address validation","severity":"high","exploited":false,"published_at":"2026-08-13T21:17:44.7+00:00","url":"https://junglewise.ai/threats/cve-2026-18193-ibm-i-security-restriction-bypass-via-improper-address-validation"},{"cve":"CVE-2026-17223","cvss":8.8,"epss":0.0075,"slug":"cve-2026-17223-ibm-i-buffer-overflow-in-host-servers-remote-code-execution","title":"IBM i buffer overflow in host servers remote code execution","severity":"high","exploited":false,"published_at":"2026-08-13T20:17:19.097+00:00","url":"https://junglewise.ai/threats/cve-2026-17223-ibm-i-buffer-overflow-in-host-servers-remote-code-execution"},{"cve":"CVE-2026-16975","cvss":8.8,"epss":0.0075,"slug":"cve-2026-16975-ibm-i-heap-based-buffer-overflow-in-remote-code-execution","title":"IBM i heap-based buffer overflow in remote code execution","severity":"high","exploited":false,"published_at":"2026-08-13T20:17:17.24+00:00","url":"https://junglewise.ai/threats/cve-2026-16975-ibm-i-heap-based-buffer-overflow-in-remote-code-execution"},{"cve":"CVE-2026-18683","cvss":8.8,"epss":0.0067,"slug":"cve-2026-18683-ibm-i-privilege-escalation-in-navigator-for-i","title":"IBM i privilege escalation in Navigator for i","severity":"high","exploited":false,"published_at":"2026-08-12T17:17:25.79+00:00","url":"https://junglewise.ai/threats/cve-2026-18683-ibm-i-privilege-escalation-in-navigator-for-i"},{"cve":"CVE-2026-18847","cvss":8.8,"epss":0.0025,"slug":"cve-2026-18847-ibm-i-credential-harvesting-via-navigator-spoofing","title":"IBM i credential harvesting via Navigator spoofing","severity":"high","exploited":false,"published_at":"2026-08-12T17:17:25.92+00:00","url":"https://junglewise.ai/threats/cve-2026-18847-ibm-i-credential-harvesting-via-navigator-spoofing"},{"cve":"CVE-2026-17029","cvss":8.8,"epss":0.0017,"slug":"cve-2026-17029-ibm-i-out-of-bounds-write-in-java-secure-sockets-extension","title":"IBM i out-of-bounds write in Java Secure Sockets Extension","severity":"high","exploited":false,"published_at":"2026-08-13T20:17:17.84+00:00","url":"https://junglewise.ai/threats/cve-2026-17029-ibm-i-out-of-bounds-write-in-java-secure-sockets-extension"},{"cve":"CVE-2026-16987","cvss":8.8,"epss":0.0015,"slug":"cve-2026-16987-ibm-i-lang-environment-variable-privilege-escalation-in-pase","title":"IBM i LANG environment variable privilege escalation in PASE","severity":"high","exploited":false,"published_at":"2026-08-13T20:17:17.53+00:00","url":"https://junglewise.ai/threats/cve-2026-16987-ibm-i-lang-environment-variable-privilege-escalation-in-pase"},{"cve":"CVE-2026-18101","cvss":8.8,"epss":0.0014,"slug":"cve-2026-18101-ibm-i-privilege-escalation-in-thread-authority-management","title":"IBM i privilege escalation in thread authority management","severity":"high","exploited":false,"published_at":"2026-08-13T21:17:44.55+00:00","url":"https://junglewise.ai/threats/cve-2026-18101-ibm-i-privilege-escalation-in-thread-authority-management"},{"cve":"CVE-2026-7870","cvss":8.8,"slug":"cve-2026-7870-ibm-i-privilege-escalation-via-unqualified-library-call","title":"IBM i privilege escalation via unqualified library call","severity":"high","exploited":false,"published_at":"2026-06-11T16:16:25.22+00:00","url":"https://junglewise.ai/threats/cve-2026-7870-ibm-i-privilege-escalation-via-unqualified-library-call"},{"cve":"CVE-2026-16908","cvss":8.5,"epss":0.0058,"slug":"cve-2026-16908-ibm-i-path-traversal-in-sql","title":"IBM i path traversal in SQL","severity":"high","exploited":false,"published_at":"2026-08-13T20:17:16.667+00:00","url":"https://junglewise.ai/threats/cve-2026-16908-ibm-i-path-traversal-in-sql"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}