CVE-2026-16816: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIX 7.2to a version that resolves this vulnerability.Patch SPKEY7.2.5IJ5956608 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308 - Configuration
When applying these AIX/VIOS patches using nimsh secure, follow the special steps required because the protocol between master and client is updated to be more secure.
NIMSH secure nimsh secure protocol = updated - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
- Operational
After updating the AIX service pack (SP) or VIOS fix pack (FP), perform an LPAR reboot to complete the SP/FP update.
Event History
Frequently Asked Questions
Which products should be assessed for exposure?
IBM AIX and IBM PowerVM VIOS are listed as affected software.