CVE-2026-16690: Vulnerabilities in IBM AIX and PowerVM VIOS
Published Aug 15, 2026
·Updated
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
Affected Software
10 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
IBM VIOS>=4.1.0<4.1.0.50
IBM VIOS>=4.1.1.0<4.1.1.30
IBM VIOS>=4.1.2.0<4.1.2.20
IBM AIX>=7.2.5<=7.2.5.212
IBM AIX>=7.3.2<=7.3.2.5
IBM AIX>=7.3.3<=7.3.3.2
IBM AIX>=7.3.4<=7.3.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308/14/2026 - Operational
Perform an LPAR reboot after completing the SP/FP update to complete the AIX/VIOS remediation.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, take the additional steps required to migrate to the latest Postgres15.
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 19, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software