Technology · IBM
IBM PowerVM VIOS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 73 vulnerabilities in IBM PowerVM VIOS: 0 in the last 7 days and 73 in the last 90 days, 12 of them critical and 0 exploited in the wild. The most recent, CVE-2026-16821, was published on 28 August 2026.
- Last 7 days
- 0
- Last 90 days
- 73
- Critical, all time
- 12
- Exploited in the wild
- 0
Latest IBM PowerVM VIOS vulnerabilities
- CVE-2026-16821: IBM AIX format string vulnerability in privileged componenthighCVSS 7EPSS 0.1%
- CVE-2026-19783: IBM AIX and PowerVM VIOS kernel memory corruption in directory readsmediumCVSS 6.7EPSS 0.1%
- CVE-2026-19449: IBM AIX and PowerVM VIOS cmdnim privilege escalationhighCVSS 8.8EPSS 0.1%
- CVE-2026-19448: IBM AIX and PowerVM VIOS IPsec ESP stack memory corruptionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-19446: IBM AIX and PowerVM VIOS RPC DoS via malformed UDP packethighCVSS 7.5EPSS 1.0%
- CVE-2026-19442: IBM AIX pointer validation flaw in Virtual SCSI initiatorhighCVSS 8.2EPSS 0.1%
- CVE-2026-18842: IBM AIX and PowerVM VIOS out-of-bounds write privilege escalationhighCVSS 8.4EPSS 0.1%
- CVE-2026-18840: IBM AIX and PowerVM VIOS code execution via pointer validationhighCVSS 8.2EPSS 0.1%
- CVE-2026-18835: IBM AIX and PowerVM VIOS command injection vulnerabilitycriticalCVSS 9.9EPSS 0.8%
- CVE-2026-18832: IBM AIX and PowerVM VIOS heap-based buffer overflowhighCVSS 8.8EPSS 0.6%
- CVE-2026-18828: IBM AIX and PowerVM VIOS stack-based buffer overflowmediumCVSS 5.4EPSS 0.4%
- CVE-2026-18824: IBM AIX and PowerVM VIOS OS command injectionhighCVSS 8.4EPSS 0.4%
- CVE-2026-18822: IBM AIX and PowerVM VIOS denial of service via directory parsingmediumCVSS 4.4EPSS 0.1%
- CVE-2026-18716: IBM AIX and PowerVM VIOS out-of-bounds readhighCVSS 7.9EPSS 0.3%
- CVE-2026-18670: IBM AIX and PowerVM VIOS integer underflow denial of service and information disclosurehighCVSS 8.2EPSS 0.4%
- CVE-2026-17436: IBM AIX heap-based buffer overflow in NIMhighCVSS 8.8EPSS 0.6%
- CVE-2026-17425: IBM AIX and PowerVM VIOS stack buffer overflowhighCVSS 7.5EPSS 0.5%
- CVE-2026-17424: IBM AIX pathname security bypassmediumCVSS 4.8EPSS 0.3%
- CVE-2026-17423: IBM AIX and PowerVM VIOS out-of-bounds readhighCVSS 7.7EPSS 0.3%
- CVE-2026-17195: IBM AIX and PowerVM VIOS out-of-bounds write denial of servicemediumCVSS 6.5EPSS 0.1%
- CVE-2026-17171: IBM AIX and PowerVM VIOS arbitrary file overwrite via symlink followinghighCVSS 7.8EPSS 0.2%
- CVE-2026-17170: IBM AIX and PowerVM VIOS denial of service via improper allocation validationhighCVSS 7.5EPSS 0.5%
- CVE-2026-17168: IBM AIX and PowerVM VIOS stack-based buffer overflowhighCVSS 8.5EPSS 0.4%
- CVE-2026-17165: IBM AIX and PowerVM VIOS NULL pointer dereference denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-17163: IBM AIX and PowerVM VIOS denial of service via improper array validationhighCVSS 7.5EPSS 0.5%
Most severe IBM PowerVM VIOS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-18835: IBM AIX and PowerVM VIOS command injection vulnerabilitycriticalCVSS 9.9EPSS 0.8%
- CVE-2026-17142: IBM AIX and PowerVM VIOS NIM authentication bypasscriticalCVSS 9.8EPSS 0.9%
- CVE-2026-17160: IBM AIX and PowerVM VIOS integer overflow in size computationcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17157: IBM AIX and PowerVM VIOS stack buffer overflow remote code executioncriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17152: IBM AIX and PowerVM VIOS buffer overflow remote code executioncriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17141: IBM AIX buffer overflow in NIMcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17136: IBM AIX and PowerVM VIOS format string vulnerability in NIMcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17122: IBM AIX and PowerVM VIOS stack-based buffer overflowcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17118: IBM AIX and PowerVM VIOS use-after-free remote code executioncriticalCVSS 9.8EPSS 0.8%
- CVE-2026-17040: IBM AIX and PowerVM VIOS buffer overflowcriticalCVSS 9.8EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 72 | 12 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/powervm-vios.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "IBM PowerVM VIOS vulnerabilities", https://junglewise.ai/threats/technologies/powervm-vios, 26 September 2026.