CVE-2026-16816: Vulnerabilities in IBM AIX and PowerVM VIOS
AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY7.2.5IJ5956608/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Operational
For the AIX SP/FP update, perform an LPAR reboot to complete the SP/FP update.
- Operational
If running VIOS 4.1.0 or VIOS 4.1.1, perform the additional required steps to migrate to the latest Postgres15 after applying the VIOS 4.1.0.50 or 4.1.1.30 fixes.
Event History
Frequently Asked Questions
Which products should be assessed for exposure?
IBM AIX and IBM PowerVM VIOS are listed as affected software.