CVE-2026-16815
8.6IBM · i
IBM i 7 is susceptible to an out-of-bounds write vulnerability that may allow unauthenticated remote attackers to disrupt services or compromise system memory.
Executive summary
IBM i versions 7.3 through 7.6 are vulnerable to an out-of-bounds write flaw that could result in service disruption or unauthorized system control.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) that can be triggered by an unauthenticated, remote attacker over the network. It involves the improper handling of data, which can lead to memory corruption.
Business impact
The impact of this vulnerability is severe, as it threatens both the availability and the security of the IBM i platform. A successful exploit could cause system-wide instability or allow for unauthorized code execution, posing a major risk to data integrity and business continuity. The CVSS score of 8.6 reflects the high potential for impact and the ease of remote access.
Remediation
Immediate Action: Apply the necessary PTFs for the relevant version: SJ11083 or SJ11127 for 7.4, SJ11074 or SJ11129 for 7.5, and SJ11061 or SJ11131 for 7.6.
Proactive Monitoring: Review system diagnostic logs for signs of memory-related errors or recurring process failures.
Compensating Controls: Restrict network access to the IBM i environment using network access control lists to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this issue necessitates prompt remediation. Administrators must verify their current version of IBM i and apply the corresponding PTF updates to eliminate the risk of exploitation.