IBM has disclosed several critical vulnerabilities affecting AIX 7.2, 7.3, and VIOS 3.1, 4.1 systems, specifically targeting the Network Installation Manager (NIM) services. The vulnerabilities include two arbitrary command execution flaws (CVE-2025-36250 and CVE-2025-36251), a path traversal vulnerability (CVE-2025-36236), and an issue with insufficiently protected credentials (CVE-2025-36096). These flaws allow remote attackers to execute arbitrary commands, traverse directories to write files, and potentially obtain sensitive NIM private keys through man-in-the-middle attacks, all due to improper process controls and insecure storage practices. The vulnerabilities are remotely exploitable if an attacker can establish network connectivity to the affected host, with CVSS scores ranging from 8.2 to 10, indicating high to critical severity.
IBM has released security bulletins and patches to address these vulnerabilities, which also close additional attack vectors related to previously disclosed issues (CVE-2024-56346 and CVE-2024-56347). Organizations running affected versions of AIX and VIOS are strongly advised to apply the recommended fixes immediately to mitigate the risk of remote exploitation, credential theft, and unauthorized file manipulation. The vulnerabilities impact core NIM services, including nimesis and nimsh, and highlight the importance of securing network access to critical infrastructure components.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
IBM published a security bulletin covering CVE-2025-36251 and CVE-2025-36250 (arbitrary command/code execution), CVE-2025-36096 (insufficiently protected credentials), and CVE-2025-36236 (path traversal) affecting AIX 7.2/7.3 and VIOS 3.1/4.1. The bulletin directed customers to apply security updates and harden or restrict exposed NIM/nimsh services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.