Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-16816 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-08-19 |
| Vendor | IBM |
| Product | AIX / PowerVM VIOS |
| CVSS Score | 9.9 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Required Actions
- Apply the IBM fixes per the advisory (IBM Support, node 7283858). A single update closes all four vulnerabilities.
- Treat CVE-2026-15065 separately, because the patch does not close it. Private keys of an intermediate CA were exposed in a publicly available update file. A leaked key stays compromised after any update — certificates depending on that CA must be revoked and reissued. Check the IBM advisory for the procedure.
- Operationally the most serious is CVE-2026-16656: root compromise without authentication. Until patches are applied, restrict network access to affected systems to trusted administrative segments only.
- Note VIOS: it is the Power virtualization layer, so a compromise covers every partition served by that host, not a single system.
Who Is Affected?
Organizations running IBM AIX 7.2 or 7.3 or PowerVM VIOS 4.1 — typically the financial sector and large Power environments. Systems of this class often sit in long change cycles, so also check installations considered stable and untouched.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
