IBM disclosed that IBM i NetServer is affected by 15 vulnerabilities across versions 7.3, 7.4, 7.5, and 7.6, with impacts including sensitive information disclosure, denial of service, and unauthorized access to server resources. The bulletin describes multiple weakness classes, including out-of-bounds read (CWE-125), out-of-bounds write, integer overflow, incomplete bounds checking, improper authentication, heap buffer overflow, and use of uninitialized memory. IBM said the most severe issues reach CVSS 8.6 and that no workarounds or mitigations are available.
Among the newly tracked issues, CVE-2026-16867 affects NTLM session negotiation and could let a remote attacker access server resources with the privileges of an authenticated user, while CVE-2026-16868 could allow a remote denial-of-service condition through uninitialized memory during ASN.1 length processing. IBM directed customers to apply fixes delivered in PTFs MJ10936 through MJ10939 to address the NetServer flaws.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-16868 states that psirt@us.ibm.com received the vulnerability on August 13, 2026. The issue involves use of uninitialized memory during ASN.1 length processing and could allow a remote attacker to cause a denial of service.
The CVE record for CVE-2026-16867 states that IBM PSIRT received the vulnerability on August 13, 2026. The flaw is an improper authentication issue during NTLM session negotiation that can let a remote attacker access server resources with an authenticated user's privileges.
IBM published a security bulletin stating that IBM i NetServer is affected by 15 vulnerabilities impacting IBM i versions 7.3, 7.4, 7.5, and 7.6. IBM released fixes via PTFs MJ10936 through MJ10939 and said no workarounds or mitigations are available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceibm.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.