ZeroHour

CVE-2026-17470

large

Remote buffer overflow in IBM i 7.3-7.6 allows unauthenticated DoS

CVSS 3.1
7.5 high
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-17470 is a buffer overflow (out-of-bounds write, CWE-787) in IBM i, the operating system that runs on IBM Power Systems servers, affecting releases 7.6, 7.5, 7.4, and 7.3. A remote attacker can trigger it by sending crafted network input to the affected service with no authentication or user interaction required, causing the buffer to be overflowed. Successful exploitation has no confidentiality or integrity impact per CVSS, but can crash or hang the affected service, producing a denial of service on the IBM i host. Any organization running one of the four affected IBM i releases is potentially affected, with the highest risk for systems reachable from untrusted networks. There are currently no known reports of exploitation, no public proof-of-concept, no CISA KEV listing, and a low EPSS 30-day exploitation probability of 0.4%.

What to do: Apply the corrective PTFs for each affected release (7.6, 7.5, 7.4, 7.3) listed in IBM's security bulletin for CVE-2026-17470, and verify applied fix levels using IBM i PTF checking tools such as DSPPTF. As an interim mitigation, restrict untrusted network access to IBM i services via firewall rules or system network-attribute settings. Prioritize patching IBM i hosts that are exposed to untrusted networks, since exploitation has not yet been observed in the wild.

Affected
ibm i7.6, 7.5, 7.4, and 7.3
Estimated exposure
large≈100,000+ IBM i systems worldwide (installed-base estimates), with only a small subset directly internet-exposed — Public industry estimates place the active IBM i installed base at roughly 100,000+ systems, mostly running internal back-office and ERP workloads behind corporate firewalls, so only a fraction of those on releases 7.3-7.6 would be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.

Vendors
ibm
Products
i
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.