CVE-2026-16937: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30 - Upgrade
Upgrade
PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.2.20 - Compensating control
For the SP/FP update, perform an LPAR reboot to complete the SP/FP update.
- Operational
If running VIOS 4.1.0 or VIOS 4.1.1: after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional required steps to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker can exploit the improper privilege management issue to gain elevated privileges.
Which products are identified as affected?
The affected software listed is IBM AIX and IBM PowerVM VIOS.