CVE-2026-18840: IBM AIX vulnerability
Published Aug 15, 2026
·Updated
AIX could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
Affected Software
3 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The issue is described as locally exploitable, so an attacker would need local access to an affected IBM AIX or IBM PowerVM VIOS system.