IBM disclosed a broad set of vulnerabilities affecting IBM i versions 7.3 through 7.6, with the most serious issues enabling remote code execution, privilege escalation, and security bypass. In Navigator for i, IBM reported multiple flaws including improper authorization, command injection, XML injection, unsafe reflection, and improper privilege management. The highest-rated Navigator issue, CVE-2026-17276 (CVSS 9.6), could let a remote authenticated attacker escalate privileges through high-authority thread handling, while CVE-2026-18235 could allow authenticated execution of arbitrary Control Language commands and CVE-2026-17095 could permit restriction bypass. IBM also tied the bulletin to additional high-severity weaknesses such as CVE-2026-16904 and CVE-2026-18098, which could enable arbitrary command execution or expose sensitive information.
Separate IBM i flaws addressed in the same patch cycle include CVE-2026-16860, a CVSS 9.9 uncontrolled search path issue that could lead to remote code execution with low-privileged access, and CVE-2026-17083, a CVSS 9.8 unauthenticated stack-based buffer overflow in the IBM i Debug Server that could enable remote code execution. IBM released fixes through PTFs SJ10887, SJ10888, SJ10890, and SJ10891, said no workarounds or mitigations were available for the Navigator for i bulletin, and urged customers to apply the updates immediately or move unsupported systems to fixed supported releases. Reporting on the release said there was no known active exploitation at publication, but warned that exposed Debug Server instances and enterprise IBM i systems running payroll, ERP, supply chain, and financial workloads face elevated risk until patched.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE record for CVE-2026-17101 was published describing a high-severity improper authentication flaw in IBM i Navigator for i affecting versions 7.3 through 7.6. The record said a remote attacker could exploit the issue to execute arbitrary code or obtain sensitive information and pointed users to IBM patches.
Multiple CVE entries tied to IBM's Navigator for i bulletin were published, including CVE-2026-16904, CVE-2026-17095, CVE-2026-17276, CVE-2026-18098, and CVE-2026-18235. These records described the flaws' impact and linked back to IBM's support bulletin for remediation guidance.
IBM released a broader patch cycle for IBM i 7.3 through 7.6 addressing nine vulnerabilities across platform components, including a CVSS 9.9 uncontrolled search path flaw (CVE-2026-16860), a CVSS 9.8 Debug Server buffer overflow (CVE-2026-17083), SQL injection issues, Navigator for i privilege escalation, and an activation engine root-authority script execution flaw. The advisory stated there was no known active exploitation at the time and provided version-specific PTFs.
IBM disclosed multiple vulnerabilities affecting Navigator for i on IBM i versions 7.3, 7.4, 7.5, and 7.6, including critical and high-severity flaws such as CVE-2026-17276, CVE-2026-18235, CVE-2026-16904, CVE-2026-17095, and CVE-2026-18098. IBM released PTFs SJ10887, SJ10888, SJ10890, and SJ10891 and said no workarounds or mitigations were available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcethreataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.