ZeroHour

CVE-2026-18341

large

Integer underflow memory corruption in IBM i 7.3–7.6

CVSS 3.1
8.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a flaw that could allow a remote, authenticated attacker to corrupt memory due to an integer underflow (CWE-191), leading to out-of-bounds memory writes (CWE-122). The issue is triggered by sending crafted input over the network to the affected system while holding valid, low-privilege credentials, since the attack requires no user interaction and only low privileges. Successful exploitation carries high potential impact to confidentiality, integrity, and availability, which could mean system compromise or service disruption on the IBM i partition. Any organization running IBM i 7.3 through 7.6 is potentially affected, though only systems whose affected interface is reachable over the network by authenticated users face practical risk. There is currently no known public proof-of-concept, no entry in CISA's KEV catalog, and no confirmed exploitation in the wild, with EPSS estimating only a 0.2% chance of exploitation in the next 30 days.

What to do: Review IBM's security bulletin for CVE-2026-18341 and apply the IBM i PTFs or fix levels it specifies for 7.3, 7.4, 7.5, and 7.6, since specific fixed versions are not stated in the available data. In the interim, limit remote access to IBM i network services to trusted users and networks and confirm that unauthenticated or broadly shared accounts cannot reach the affected system. Because the affected component is unspecified, inventory all IBM i partitions running 7.3–7.6 and track the advisory for updated remediation details.

Affected
IBM i7.6, 7.5, 7.4, 7.3
Estimated exposure
largeon the order of hundreds of thousands of IBM i systems potentially affected (installed base widely estimated at ~200,000–300,000+), with the directly exposed… — IBM i's long-lived midrange installed base is commonly estimated in the hundreds of thousands of installations, but the affected component is not named in the data and valid credentials are required, so the count is an upper-bound estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

Vendors
ibm
Products
i
Weakness
CWE-122, CWE-191
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.