CVE-2026-7770: IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator
IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7770?
The severity of CVE-2026-7770 is classified as high with a score of 8.8.
How does CVE-2026-7770 affect IBM i Access Client Solutions?
CVE-2026-7770 affects IBM i Access Client Solutions by allowing remote code execution when it is configured to listen for requests from IBM i Navigator.
Which versions of IBM i Access Family are impacted by CVE-2026-7770?
Versions 1.1.5.0 through 1.1.9.12 of IBM i Access Family are impacted by CVE-2026-7770.
How can I mitigate the risks associated with CVE-2026-7770?
To mitigate the risks of CVE-2026-7770, you should reconfigure IBM i Access Client Solutions to not listen for requests from IBM i Navigator or apply any available patches.
When was CVE-2026-7770 published?
CVE-2026-7770 was published on May 27, 2026.