IBM has disclosed a critical stack buffer overflow in AIX 7.2, AIX 7.3, and PowerVM VIOS 4.1 that could allow an unauthenticated remote attacker to execute arbitrary code, rated CVSS 9.8.
What Is It
CVE-2026-16862 is a stack buffer overflow (CWE-787, out-of-bounds write) affecting IBM AIX and IBM PowerVM VIOS. Per IBM's advisory, the flaw "could allow a remote attacker to execute arbitrary code."
The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8, CRITICAL. Every exploitability dimension is at its worst setting: network-reachable, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability, giving an exploitability subscore of 3.9 and an impact subscore of 5.9.
The CVE was published by IBM PSIRT ([email protected]) on 2026-08-19 and currently carries NVD status "Received," meaning NVD analysis is not yet complete.
Why It Matters
A pre-authentication remote code execution bug in AIX and VIOS lands on systems that typically host enterprise workloads and virtualization infrastructure. VIOS in particular sits underneath partitioned Power environments, so code execution there has consequences beyond a single host.
No CISA KEV entry was supplied for this CVE, so there is no confirmed evidence of active exploitation in the wild at this time and no KEV-mandated remediation deadline. That status can change; the 9.8 rating and lack of required privileges or user interaction make this a priority regardless.
What's Vulnerable
Per the IBM-supplied affected data:
- IBM AIX: 7.2 (including 7.2.0) and 7.3 (including 7.3.0)
- IBM PowerVM VIOS: 4.1 (including 4.1.0)
No other products or versions are listed in the supplied record.
Patch Status
The single reference in the NVD record is IBM Support node 7283858, which is IBM's advisory page for this issue. The supplied data does not specify fix levels, iFix names, or interim fix packages; administrators should consult the IBM advisory directly for the applicable remediation for their AIX or VIOS level. No CISA KEV required action or due date applies, as no KEV entry was provided.
Sources
- NVD, CVE-2026-16862: https://nvd.nist.gov/vuln/detail/CVE-2026-16862
- IBM Support Advisory (node 7283858): https://www.ibm.com/support/pages/node/7283858