CVE-2026-17206: IBM i is Affected By Multiple Vulnerabilities in Host Servers
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
Other sources
IBM i could allow a remote attacker to execute arbitrary code due to a buffer overflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ10848 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ10899 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11022 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11101 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11097 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11098 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11099 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11100 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11102 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11103 - Upgrade
Upgrade
IBM i (Host Servers)to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11104
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17206?
The severity of CVE-2026-17206 is rated as high with a score of 8.1.
How does CVE-2026-17206 affect IBM i systems?
CVE-2026-17206 could allow a remote attacker to execute arbitrary code due to a buffer overflow in IBM i versions 7.3 to 7.6.
What types of systems are vulnerable to CVE-2026-17206?
IBM i systems running versions 7.3, 7.4, 7.5, and 7.6 are vulnerable to CVE-2026-17206.
Can CVE-2026-17206 be exploited remotely?
Yes, CVE-2026-17206 can be exploited remotely by attackers.
What is a buffer overflow in relation to CVE-2026-17206?
A buffer overflow, in the context of CVE-2026-17206, is a flaw that allows attackers to execute arbitrary code due to improper handling of memory.