Common Vulnerabilities and Exposures (CVE)

CVE-2026-18511

Aug 13, 2026 20:43:37 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could...

CVE-2026-18509

Aug 13, 2026 20:43:18 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profile...

CVE-2026-18249

Aug 13, 2026 20:43:03 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.

CVE-2026-18193

Aug 13, 2026 20:42:46 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

CVE-2026-18101

Aug 13, 2026 20:42:27 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.

CVE-2026-18086

Aug 13, 2026 20:42:13 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

CVE-2026-18077

Aug 13, 2026 20:41:56 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.

CVE-2026-18068

Aug 13, 2026 20:41:41 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.

CVE-2026-18020

Aug 13, 2026 20:41:25 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking.

CVE-2026-17649

Aug 13, 2026 20:41:09 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

CVE-2026-17502

Aug 13, 2026 20:40:54 UTC

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

CVE-2026-17482

Aug 13, 2026 20:39:46 UTC

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

CVE-2026-17468

Aug 13, 2026 20:39:27 UTC

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.

CVE-2026-17473

Aug 13, 2026 20:39:13 UTC

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.

CVE-2026-17481

Aug 13, 2026 20:38:55 UTC

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.