IBM has disclosed a critical (CVSS 9.8) integer underflow vulnerability affecting IBM AIX 7.2 and 7.3 as well as IBM PowerVM VIOS 4.1, which a remote attacker could exploit without authentication.
What Is It
CVE-2026-16834 is an integer underflow condition (CWE-190, Integer Overflow or Wraparound) in IBM AIX and IBM PowerVM VIOS. According to IBM's advisory, the flaw could allow a remote attacker to cause a denial of service.
The CVE was published on 2026-08-19 by IBM PSIRT ([email protected]) and currently carries NVD status "Received," meaning NVD analysis is not yet complete.
Why It Matters
IBM assigned a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
That vector is about as bad as scoring gets: network-reachable attack vector, low attack complexity, no privileges required, and no user interaction; an exploitability sub-score of 3.9 out of 3.9. IBM rates the impact as HIGH across confidentiality, integrity, and availability (impact sub-score 5.9), even though the narrative description only cites denial of service. That gap between a DoS-only description and a full CIA-triad impact rating is worth noting when prioritizing internally; treat the vendor's scoring as the operative severity until NVD completes its own analysis.
AIX and VIOS underpin IBM Power infrastructure that typically runs core, hard-to-patch workloads, so an unauthenticated remote condition on these platforms deserves fast attention.
What's Vulnerable
Per IBM's affected-product data:
- IBM AIX: 7.2 (including 7.2.0) and 7.3 (including 7.3.0)
- IBM PowerVM VIOS: 4.1 (including 4.1.0)
No other products, versions, or components are listed in the supplied record.
Patch Status
IBM has published a support advisory for this issue at node 7283858. The supplied data does not specify fix package levels, iFix identifiers, or workarounds; consult the IBM advisory directly for the applicable remediation for your AIX or VIOS level.
This CVE does not appear in the supplied CISA Known Exploited Vulnerabilities catalog data, and there is no evidence of active exploitation in the source material. No KEV-mandated due date or required action applies.
Sources
- NVD, CVE-2026-16834: https://nvd.nist.gov/vuln/detail/CVE-2026-16834
- IBM Support Advisory (node 7283858): https://www.ibm.com/support/pages/node/7283858