CVE-2026-16865: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.2.20Patch key_w_apar - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in SP13Patch IJ5956608/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in SP02Patch IJ5956408/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in SP03Patch IJ59563 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in SP05Patch IJ59563 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956508/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956408/14/2026 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ59563 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch IJ5956608/14/2026 - Operational
An LPAR reboot is required to complete the SP/FP update.
Event History
Frequently Asked Questions
Which IBM products should be included in triage?
The affected software list includes IBM AIX and IBM PowerVM VIOS.