CVE-2026-17502
8.6IBM · i
IBM i 7 contains an out-of-bounds write vulnerability that could allow an unauthenticated remote attacker to cause a system crash or potentially execute arbitrary code.
Executive summary
An out-of-bounds write vulnerability in IBM i versions 7.3 through 7.6 poses a high risk to system availability and integrity due to potential memory corruption.
Vulnerability
This is an out-of-bounds write vulnerability (CWE-787) that allows an unauthenticated, remote attacker to trigger memory corruption. The vulnerability is accessible over the network without requiring user interaction or specific privileges.
Business impact
Successful exploitation of this vulnerability could lead to a complete system crash, resulting in significant downtime for critical business operations. Furthermore, the ability to perform an out-of-bounds write may allow an attacker to overwrite sensitive memory, potentially leading to unauthorized data modification or arbitrary code execution, which justifies the high CVSS score of 8.6.
Remediation
Immediate Action: Apply the appropriate Program Temporary Fix (PTF) as provided by IBM: PTF MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, or MJ10939 for 7.6.
Proactive Monitoring: Monitor system logs for unusual termination events or unexpected service restarts that may indicate attempted exploitation.
Compensating Controls: Ensure the IBM i instance is protected by a robust firewall policy that restricts network access to authorized management segments only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for system disruption and the ease of network-based access, organizations should prioritize the installation of the specified PTFs immediately. Failure to apply these updates leaves the system susceptible to remote crashes and unauthorized memory manipulation.