CVE-2026-17274: IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published Aug 31, 2026
·Updated
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
Other sources
IBM i could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
— IBM
Affected Software
4 affected components
IBM i<=7.6
IBM i<=7.5
IBM i<=7.4
IBM i<=7.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11308
Event History
Aug 31, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated. The available information does not indicate that unauthenticated attackers can exploit it.