ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-16836 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17006 | Medium | 0.4% | 8.3 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-81540 | Medium | 0.4% | 8.5 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-14529 | Medium | 0.4% | 9.4 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv… | |
| CVE-2026-78573 | Medium | 0.4% | 9.8 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker t… | |
| CVE-2026-17425 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16982 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17220 | Medium | 0.4% | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-18846 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly v… | |
| CVE-2026-80424 | Medium | 0.4% | 9.1 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-17181 | Medium | 0.4% | 9.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write fi… | |
| CVE-2026-17206 | Medium | 0.4% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary … | |
| CVE-2026-17121 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17159 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17163 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17165 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17170 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16852 | Medium | 0.4% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16887 | Medium | 0.4% | 7.5 | IBM i 7.6 could allow a remote attacker to cause a denial of service due to an o… | |
| CVE-2026-16931 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17004 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17199 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17229 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17271 | Medium | 0.4% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-16839 | Medium | 0.4% | 9.4 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o… | |
| CVE-2026-17095 | Medium | 0.4% | 8.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypa… | |
| CVE-2026-8850 | Medium | 0.4% | 7.5 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional… | |
| CVE-2026-14974 | Medium | 0.4% | 8.1 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a… | |
| CVE-2026-18670 | Medium | 0.4% | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-12005 | Medium | 0.4% | 7.2 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-12618 | Medium | 0.4% | 7.2 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-17060 | Medium | 0.4% | 8.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o… | |
| CVE-2026-4051 | Medium | 0.4% | 7.2 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an atta… | |
| CVE-2026-11714 | Medium | 0.4% | 8.5 | IBM WebSphere Application Server Liberty is affected by a server-side request fo… | |
| CVE-2026-17081 | Medium | 0.4% | 8.2 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write ar… | |
| CVE-2025-36254 | Medium | 0.4% | 7.4 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0… | |
| CVE-2026-8854 | Medium | 0.4% | 7.5 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional… | |
| CVE-2026-16857 | Medium | 0.4% | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to m… | |
| CVE-2026-3603 | Medium | 0.4% | 7.1 | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix … | |
| CVE-2026-16868 | Medium | 0.4% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-82097 | Medium | 0.4% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-16856 | Medium | 0.4% | 8.8 | IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due … | |
| CVE-2026-75624 | Medium | 0.4% | 8.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.… | |
| CVE-2026-13105 | Medium | 0.4% | 8.8 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip… | |
| CVE-2026-10025 | Medium | 0.3% | 8.2 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00… | |
| CVE-2026-12004 | Medium | 0.3% | 8.7 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-17197 | Medium | 0.3% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re… | |
| CVE-2026-11536 | Medium | 0.3% | 8.5 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execu… | |
| CVE-2026-16863 | Medium | 0.3% | 7.7 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta… | |
| CVE-2026-17272 | Medium | 0.3% | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … |