CVE-2026-17168
published 2026-08-20CVE-2026-17168: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.44%
37.0th percentile
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | 7.2.5 – 7.2.5.212 | — |
| ibm | aix | 7.3.2 – 7.3.2.5 | — |
| ibm | aix | 7.3.3 – 7.3.3.2 | — |
| ibm | aix | 7.3.4 – 7.3.4.1 | — |
| ibm | powervm_vios | — | — |
| ibm | vios | >= 4.1.0 < 4.1.0.50 | 4.1.0.50 |
| ibm | vios | >= 4.1.1.0 < 4.1.1.30 | 4.1.1.30 |
| ibm | vios | >= 4.1.2.0 < 4.1.2.20 | 4.1.2.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
ghsa_unreviewed·2026-08-21
CVE-2026-17168 [HIGH] CWE-787 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow.
VulDB
IBM AIX/PowerVM VIOS buffer overflow
vuldb·2026-08-21·CVSS 8.5
CVE-2026-17168 [HIGH] IBM AIX/PowerVM VIOS buffer overflow
A vulnerability was found in IBM AIX and PowerVM VIOS. It has been declared as very critical. This vulnerability affects unknown code. The manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2026-17168. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-20
Published