CVE-2026-16936: Vulnerabilities in IBM AIX and PowerVM VIOS
Published Aug 15, 2026
·Updated
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
Affected Software
10 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
IBM VIOS>=4.1.0<4.1.0.50
IBM VIOS>=4.1.1.0<4.1.1.30
IBM VIOS>=4.1.2.0<4.1.2.20
IBM AIX>=7.2.5<=7.2.5.212
IBM AIX>=7.3.2<=7.3.2.5
IBM AIX>=7.3.3<=7.3.3.2
IBM AIX>=7.3.4<=7.3.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Operational
Reboot the LPAR to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update).
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform the additional required steps to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 20, 2026
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
RemedyDescriptionSeverityWeaknessAffected Software