CVE-2026-16860: IBM i is Affected By Remote Code Execution Vulnerability []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
Other sources
IBM i could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ10879 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ10880 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ10881 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ10882
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16860?
The severity of CVE-2026-16860 is rated critical with a score of 9.9.
How do I fix CVE-2026-16860?
To fix CVE-2026-16860, ensure that all IBM i systems are updated to the latest available patches provided by IBM.
What systems are affected by CVE-2026-16860?
CVE-2026-16860 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
What type of vulnerability is CVE-2026-16860?
CVE-2026-16860 is a remote code execution vulnerability that can be exploited by an authenticated attacker.
What can an attacker do with CVE-2026-16860?
An attacker exploiting CVE-2026-16860 can execute arbitrary code on the affected IBM i systems.