CVE-2026-16964: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.0.50 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.1.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.2.20 - Compensating control
If using nimsh secure to apply VIOS/AIX patches, follow the required nimsh secure special steps because the protocol between master and client is updated to be more secure.
- Operational
Reboot the LPAR is required to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional required steps to migrate to the latest Postgres15.
Event History
Frequently Asked Questions
Which systems should be included in triage?
IBM AIX and IBM PowerVM VIOS are identified as affected software. No affected versions are provided in the available data.
Does an attacker need local access to exploit this issue?
No. The issue is described as allowing a remote attacker to intercept messages and forge replies.