CVE-2026-17470
largeRemote buffer overflow in IBM i 7.3-7.6 allows unauthenticated DoS
CVE-2026-17470 is a buffer overflow (out-of-bounds write, CWE-787) in IBM i, the operating system that runs on IBM Power Systems servers, affecting releases 7.6, 7.5, 7.4, and 7.3. A remote attacker can trigger it by sending crafted network input to the affected service with no authentication or user interaction required, causing the buffer to be overflowed. Successful exploitation has no confidentiality or integrity impact per CVSS, but can crash or hang the affected service, producing a denial of service on the IBM i host. Any organization running one of the four affected IBM i releases is potentially affected, with the highest risk for systems reachable from untrusted networks. There are currently no known reports of exploitation, no public proof-of-concept, no CISA KEV listing, and a low EPSS 30-day exploitation probability of 0.4%.
What to do: Apply the corrective PTFs for each affected release (7.6, 7.5, 7.4, 7.3) listed in IBM's security bulletin for CVE-2026-17470, and verify applied fix levels using IBM i PTF checking tools such as DSPPTF. As an interim mitigation, restrict untrusted network access to IBM i services via firewall rules or system network-attribute settings. Prioritize patching IBM i hosts that are exposed to untrusted networks, since exploitation has not yet been observed in the wild.
| ibm i | 7.6, 7.5, 7.4, and 7.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.