CVE-2026-18835: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
IBM PowerVM VIOSto a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY7.2.5IJ5956608/14/2026 - Upgrade
Upgrade
IBM AIXto a version that resolves this vulnerability.Patch SPKEY4.1.0IJ5956508/14/2026 - Compensating control
For VIOS 4.1.0 and VIOS 4.1.1, after applying the 4.1.0.50 or 4.1.1.30 FPs, perform the additional steps required to migrate to the latest Postgres15 (as noted in the advisory).
- Operational
Perform an LPAR reboot to complete the SP/FP update (an LPAR reboot is required to complete the SP/FP update).
Event History
Frequently Asked Questions
Which systems should be prioritized for review?
IBM AIX and IBM PowerVM VIOS are identified as affected software. Prioritize systems where authenticated users can access these products remotely.
What level of access does an attacker need?
An attacker must be remote and authenticated. The provided information does not identify any unauthenticated exploitation path.