CVE-2026-16887
Undergoing Analysis Undergoing Analysis - In Progress

Denial of Service in IBM i 7.6 via Out-of-Bounds Write

Vulnerability report for CVE-2026-16887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: IBM Corporation

Description

IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm ibm_i 7.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM i 7.6 is vulnerable to a denial of service (DoS) attack due to an out-of-bounds write flaw in Dedicated System Tools (DST) and System Service Tools (SST). A remote attacker could exploit this to disrupt system operations without gaining access or altering data.

Detection Guidance

Detection involves checking for IBM i 7.6 systems with unpatched Dedicated System Tools (DST) or System Service Tools (SST) components. Monitor for unusual network traffic targeting IBM i ports or system crashes. Use IBM i commands like DSPPTF to verify PTF status and ensure MJ10909 is applied.

Impact Analysis

This vulnerability could cause system downtime or instability, leading to service disruptions. Since it affects availability, it may impact business operations relying on IBM i 7.6 systems. No confidentiality or integrity impact is expected.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by disrupting system availability. A denial of service (DoS) attack may lead to unauthorized downtime, potentially violating availability requirements in these regulations. However, since the vulnerability does not affect confidentiality or integrity, its direct impact on compliance may be limited unless availability is explicitly required.

Mitigation Strategies

Apply the provided PTF MJ10909 immediately to fix the out-of-bounds write vulnerability. If unable to patch, isolate the IBM i 7.6 system from untrusted networks to reduce exposure. Upgrade to a supported IBM i version if running an unsupported release.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16887. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart