IBM disclosed a critical (CVSS 9.3) certificate validation flaw in AIX 7.2/7.3 and PowerVM VIOS 4.1 that, according to IBM's advisory, could allow a remote, unauthenticated attacker to impersonate the TNC policy server and modify traffic.
What Is It
CVE-2026-16822 is an improper certificate validation issue (CWE-295) affecting IBM AIX and IBM PowerVM VIOS. Per IBM's advisory, the flaw "could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation."
Because the affected component does not properly validate the certificate presented by the TNC (Trusted Network Connect) policy server, an attacker positioned to answer or intercept that traffic could pose as the legitimate policy server. The described result is an attacker-in-the-middle condition against a trust-decision channel. IBM's bulletin does not detail the exploitation prerequisites beyond the CVSS vector, so the practical network positioning required is not specified in the available source material.
Why It Matters
The CVSS 3.1 base score is 9.3 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N. The exploitability sub-score is the maximum 3.9: attack vector is network, complexity is low, and neither privileges nor user interaction are required.
The impact profile is integrity-driven, HIGH integrity impact, LOW confidentiality, no availability impact, with a CHANGED scope, meaning successful exploitation affects resources beyond the vulnerable component itself. That scope change is what pushes an otherwise moderate impact set into critical territory: per the vendor's description, an attacker who impersonates the policy server could influence trust decisions and alter traffic for systems relying on it. Note that this score is IBM's own CNA assessment; NVD has not yet published an independent analysis.
What's Vulnerable
Per the IBM-supplied affected data:
- IBM AIX: 7.2 (including 7.2.0) and 7.3 (including 7.3.0)
- IBM PowerVM VIOS: 4.1 (including 4.1.0)
Patch Status
The CVE record was published 2026-08-19 with a vulnStatus of "Received," meaning NVD analysis is not yet complete. The only supplied reference is IBM's support bulletin (node 7283858), sourced from IBM PSIRT, administrators should consult it directly for fix levels and interim mitigations.
No CISA KEV entry was supplied for CVE-2026-16822. There is no confirmation of active exploitation in the provided source material, and no KEV-mandated remediation deadline or required action applies.
Sources
- NVD, CVE-2026-16822: https://nvd.nist.gov/vuln/detail/CVE-2026-16822
- IBM Support (PSIRT advisory): https://www.ibm.com/support/pages/node/7283858