CVE-2026-17083
9.8IBM · i
IBM i versions 7.3 through 7.6 are affected by a stack-based buffer overflow vulnerability that allows remote, unauthenticated attackers to execute arbitrary code.
Executive summary
A critical buffer overflow vulnerability in IBM i allows unauthenticated remote attackers to execute arbitrary code, posing a severe threat to system security.
Vulnerability
The software fails to properly handle data bounds, resulting in a stack-based buffer overflow. This allows an unauthenticated remote attacker to corrupt system memory and potentially gain full control over the affected system.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code with the privileges of the IBM i system represents a total compromise of the platform. With a CVSS score of 9.8, the business impact includes potential data exfiltration, permanent loss of system availability, and the inability to trust the integrity of processed business transactions.
Remediation
Immediate Action: Apply the specific Program Temporary Fix (PTF) for your version: 7.6 (SJ10899), 7.5 (SJ10903), 7.4 (SJ10915), or 7.3 (SJ10916).
Proactive Monitoring: Monitor system logs for unauthorized access attempts, abnormal memory usage, or unexpected system crashes that may indicate exploitation attempts.
Compensating Controls: Restrict network access to the IBM i management interfaces to trusted IP addresses only and ensure that perimeter firewalls block all unnecessary traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability is extreme. System administrators must prioritize the installation of the specified PTFs immediately, as the lack of authentication required to trigger the overflow makes this a high-priority target for threat actors.