CVE-2026-19446: IBM AIX vulnerability
Published Aug 15, 2026
·Updated
AIX allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.
Affected Software
3 affected components
IBM AIX<=7.2
IBM AIX<=7.3
IBM PowerVM VIOS<=4.1
Event History
Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What access does an attacker need to trigger the denial of service?
An attacker does not need authentication. They need network reachability to an RPC service that can receive the crafted UDP packet.
2
What is the operational impact if exploitation succeeds?
Successful exploitation causes complete system unavailability. Recovery requires restarting the affected LPAR.
3
Which products should be assessed for exposure?
Assess IBM AIX and IBM PowerVM VIOS systems, particularly LPARs with reachable RPC services exposed to networks accessible by untrusted remote users.