CVE-2026-17207
largeUnauthenticated Buffer Overflow in IBM i Enables DoS and Integrity Attacks
IBM i releases 7.3 through 7.6 contain a buffer overflow (out-of-bounds write, CWE-787) that can be triggered by a remote attacker over the network with no credentials and no user interaction, given the low-complexity attack vector. Successful exploitation causes a denial of service and allows compromise of integrity, meaning an attacker can disrupt the system and potentially alter data, though confidentiality (data disclosure) is not rated as impacted. Any organization running an affected IBM i release is exposed, particularly where IBM i services are reachable from untrusted networks. As of now there are no known public proofs of concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS estimates only a 0.3% probability of exploitation within 30 days. Defenders should treat this as a critical-rated flaw awaiting patching rather than an actively exploited emergency.
What to do: Check IBM's security advisory for CVE-2026-17207 and apply the IBM-supplied fixes (PTFs) for your release level (7.3, 7.4, 7.5, or 7.6) as soon as they are published. In the meantime, restrict network access to IBM i services from untrusted networks and firewall or VPN-front any IBM i hosts that must remain reachable. Monitor IBM's advisory for updated fix information, since no fixed release levels were specified in the initial disclosure.
| IBM i | 7.3, 7.4, 7.5, 7.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.