CVE-2026-18076: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
Other sources
IBM i could allow a remote authenticated attacker to cause a denial of service due to a memory leak.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11308
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running IBM i 7.3, 7.4, 7.5, or 7.6 with the affected Debug Server are exposed to a remote denial-of-service condition.
What access does an attacker need?
An attacker must be remotely reachable and authenticated. No user interaction is required, and the attack complexity is low.
What is the expected impact?
Successful exploitation can cause a denial of service through a memory leak. The provided severity vector indicates no stated confidentiality or integrity impact.