CVE-2026-18835: IBM AIX vulnerability
Published Aug 15, 2026
·Updated
AIX could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Affected Software
3 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which systems should be prioritized for review?
IBM AIX and IBM PowerVM VIOS are identified as affected software. Prioritize systems where authenticated users can access these products remotely.
2
What level of access does an attacker need?
An attacker must be remote and authenticated. The provided information does not identify any unauthenticated exploitation path.