| CVE-2026-16816 | 9.9 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com | 17d ago |
| CVE-2026-17186 | 9.9 | critical | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to impro | 22d ago |
| CVE-2026-16860 | 9.9 | critical | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncon | 24d ago |
| CVE-2026-15068 | 9.9 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary | 17d ago |
| CVE-2026-18835 | 9.9 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com | 16d ago |
| CVE-2026-17152 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-17145 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro | 16d ago |
| CVE-2026-17142 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 16d ago |
| CVE-2026-17141 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-17136 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a for | 16d ago |
| CVE-2026-17122 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 16d ago |
| CVE-2026-17118 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use | 16d ago |
| CVE-2026-17040 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf | 16d ago |
| CVE-2026-12943 | 9.8 | critical | hardware management console | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Po | 37d ago |
| CVE-2026-16919 | 9.8 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro | 17d ago |
| CVE-2026-16917 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in | 17d ago |
| CVE-2026-16913 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16894 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16885 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16882 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 17d ago |
| CVE-2026-16872 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16864 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16862 | 9.8 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 17d ago |
| CVE-2026-16845 | 9.8 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea | 17d ago |
| CVE-2026-16834 | 9.8 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an | 17d ago |
| CVE-2026-16956 | 9.8 | critical | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper | 24d ago |
| CVE-2026-17218 | 9.8 | critical | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write | 24d ago |
| CVE-2026-15435 | 9.8 | critical | app connect enterprise | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke | 37d ago |
| CVE-2026-14512 | 9.8 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserializati | 39d ago |
| CVE-2026-16656 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to imprope | 17d ago |
| CVE-2026-8633 | 9.8 | critical | websphere application server | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application S | 102d ago |
| CVE-2026-17083 | 9.8 | critical | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer o | 24d ago |
| CVE-2026-16840 | 9.8 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an ou | 17d ago |
| CVE-2026-9170 | 9.8 | critical | http server | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improp | 102d ago |
| CVE-2026-17157 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta | 16d ago |
| CVE-2026-3660 | 9.8 | critical | engineering lifecycle management | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to upda | 102d ago |
| CVE-2026-17184 | 9.8 | critical | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external con | 22d ago |
| CVE-2026-17182 | 9.8 | critical | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter | 22d ago |
| CVE-2026-8175 | 9.8 | critical | aspera high-speed transfer endpoint | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3. | 101d ago |
| CVE-2026-17160 | 9.8 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in | 16d ago |
| CVE-2026-17482 | 9.8 | critical | documentation offline | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro | 23d ago |
| CVE-2026-14446 | 9.8 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the a | 39d ago |
| CVE-2026-10109 | 9.8 | critical | db2 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pr | 67d ago |
| CVE-2026-12118 | 9.8 | critical | webmethods integration | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitr | 37d ago |
| CVE-2026-16903 | 9.6 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a d | 17d ago |
| CVE-2026-16835 | 9.6 | critical | power system e1080 \(9080-hex\) firmware | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu | 17d ago |
| CVE-2026-16687 | 9.6 | critical | power system e1180 \(9080-heu\) firmware | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu | 17d ago |
| CVE-2026-17276 | 9.6 | critical | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper au | 24d ago |
| CVE-2026-14529 | 9.4 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0 | 38d ago |
| CVE-2026-14525 | 9.4 | critical | websphere application server | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is v | 23d ago |
| CVE-2026-16839 | 9.4 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to | 17d ago |
| CVE-2026-11712 | 9.3 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr | 67d ago |
| CVE-2026-15091 | 9.3 | critical | engineering ai hub | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to i | 50d ago |
| CVE-2026-11708 | 9.3 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr | 67d ago |
| CVE-2026-17422 | 9.3 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buff | 16d ago |
| CVE-2026-17181 | 9.3 | critical | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to | 22d ago |
| CVE-2026-14973 | 9.3 | critical | aspera | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the us | 39d ago |
| CVE-2026-16822 | 9.3 | critical | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server a | 17d ago |
| CVE-2026-11707 | 9.3 | critical | websphere application server | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-s | 37d ago |
| CVE-2026-3627 | 9.1 | critical | concert | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. | 8d ago |
| CVE-2026-8644 | 9.1 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | 96d ago |
| CVE-2026-15065 | 9.1 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions du | 17d ago |
| CVE-2026-12628 | 9.1 | critical | storage protect | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8. | 75d ago |
| CVE-2026-7876 | 9.1 | critical | aspera high-speed transfer server for cloud pak for integration | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. | 101d ago |
| CVE-2026-14959 | 9.1 | critical | aspera faspex | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d | 39d ago |
| CVE-2026-16926 | 9.1 | critical | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to im | 16d ago |
| CVE-2026-9074 | 9.1 | critical | api connect | IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection v | 59d ago |
| CVE-2026-14958 | 9.1 | critical | aspera faspex | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d | 39d ago |
| CVE-2026-9319 | 9 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserializati | 96d ago |
| CVE-2026-9311 | 9 | critical | websphere application server | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of securi | 96d ago |
| CVE-2026-18099 | 8.9 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to i | 24d ago |
| CVE-2026-18193 | 8.9 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validat | 23d ago |
| CVE-2026-16848 | 8.8 | high | aix | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i | 17d ago |
| CVE-2026-19449 | 8.8 | high | vios | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local u | 16d ago |
| CVE-2026-5065 | 8.8 | high | controller | IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptograp | 101d ago |
| CVE-2026-8179 | 8.8 | high | aspera high-speed transfer endpoint | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3. | 101d ago |
| CVE-2026-7770 | 8.8 | high | i access client solutions | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execu | 96d ago |
| CVE-2026-7870 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. | 86d ago |
| CVE-2026-14522 | 8.8 | high | app connect enterprise | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke | 37d ago |
| CVE-2026-18683 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. | 24d ago |
| CVE-2026-18847 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing | 24d ago |
| CVE-2026-16856 | 8.8 | high | i | IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of spec | 24d ago |
| CVE-2026-16906 | 8.8 | high | i | IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privile | 24d ago |
| CVE-2026-17110 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain | 24d ago |
| CVE-2026-18669 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vuln | 24d ago |
| CVE-2026-18713 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. | 24d ago |
| CVE-2026-13361 | 8.8 | high | informix dynamic server | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | 24d ago |
| CVE-2026-17082 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improp | 24d ago |
| CVE-2026-17417 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 24d ago |
| CVE-2026-17642 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr | 24d ago |
| CVE-2026-13105 | 8.8 | high | i access client solutions | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when impor | 24d ago |
| CVE-2026-16674 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untru | 23d ago |
| CVE-2026-16722 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to | 23d ago |
| CVE-2026-16975 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-b | 23d ago |
| CVE-2026-16987 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation o | 23d ago |
| CVE-2026-17029 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write. | 23d ago |
| CVE-2026-17223 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer | 23d ago |
| CVE-2026-17481 | 8.8 | high | documentation offline | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro | 23d ago |
| CVE-2026-18101 | 8.8 | high | i | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management o | 23d ago |
| CVE-2026-16879 | 8.8 | high | db2 mirror for i | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions | 22d ago |