CVE-2026-16822: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch 4.1.0IJ5956508/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch 4.1.1IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch 4.1.2IJ5956308/14/2026 - Operational
After applying the AIX Service Pack/VIOS Fix Pack remediation levels, perform an LPAR reboot to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which IBM products are listed as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.
Does exploitation require local access to the affected system?
The issue is described as exploitable by a remote attacker. The provided information does not indicate that local access is required.