CVE-2026-18068: IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
Other sources
IBM i could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11036 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11069 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11070 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11072 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11073 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11075 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11076 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11077 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11082 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11085 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11086 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11087 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11088 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch SJ11067 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ11071 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ11068 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ11087 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ11088
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18068?
The severity of CVE-2026-18068 is medium, with a score of 4.3.
How do I fix CVE-2026-18068?
To fix CVE-2026-18068, ensure that your IBM i systems are updated to the latest patches provided by IBM.
What systems are affected by CVE-2026-18068?
CVE-2026-18068 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
What type of vulnerability is CVE-2026-18068?
CVE-2026-18068 is classified as an information leakage vulnerability due to byte-count and element-count confusion.
Can CVE-2026-18068 be exploited remotely?
Yes, CVE-2026-18068 allows a remote attacker to potentially obtain sensitive information from affected IBM i systems.