CVE-2026-18086: IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
Other sources
IBM i could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6 Release5770-JV1to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11036 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11069 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11070 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11072 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11073 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11075 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11076 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11077 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11082 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11085 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11086 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11087 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11088 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11067 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11071 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11068
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18086?
CVE-2026-18086 has a medium severity rating of 4.5.
How do I fix CVE-2026-18086?
To address CVE-2026-18086, ensure that your IBM i systems are updated to the latest patches provided by IBM.
What systems are affected by CVE-2026-18086?
CVE-2026-18086 affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What impacts can CVE-2026-18086 have on my system?
CVE-2026-18086 could allow a local attacker to execute arbitrary code or cause a denial of service.
How does CVE-2026-18086 exploit improper bounds checking?
CVE-2026-18086 exploits improper bounds checking in the Java Secure Sockets Extension on IBM i systems.