Sceawere
Vulnerability Detail
CVE-2026-16887UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Out-of-Bounds Write Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-13T20:17:16.263Z",
"pubdate": "2026-08-13T20:17:16.263Z",
"executiveSummary": "A vulnerability has been identified in IBM i 7.6 that exposes the system to a denial of service condition stemming from an out-of-bounds write flaw.\nThis vulnerability allows a remote attacker to corrupt memory by writing data past the designated buffer boundaries, leading to application crashes, instability, or complete system unavailability.\nThe affected product is IBM i version 7.6, which plays a critical role in enterprise workload management and core transactional processing.\nThe risk implications are severe for environments relying on continuous availability, as an unauthenticated or remote threat actor can disrupt critical business operations without necessarily requiring privileged access.\nExploitation requires network connectivity to the target system and the ability to deliver a crafted payload designed to trigger the out-of-bounds write condition within the vulnerable component.\nOrganizations operating the affected version face operational disruption risks and must prioritize defensive hardening and official vendor remediations as they become available.",
"technicalDetails": "The vulnerability is rooted in an out-of-bounds write memory corruption flaw present in IBM i 7.6.\nAn out-of-bounds write occurs when software writes data past the end, or before the beginning, of the intended buffer or memory allocation structure.\nIn this specific context, the vulnerable component fails to perform adequate bounds checking and input validation on data received during network processing.\nThe attack vector is network-based, allowing a remote adversary to interact with vulnerable services exposed by IBM i 7.6.\nThe attack flow commences when the remote attacker transmits a maliciously crafted network payload designed to exceed the allocated memory boundaries of the target buffer.\nUpon receiving the malformed input, the affected subsystem processes the data without proper length verification, causing the execution flow to write attacker-controlled values or application artifacts into adjacent memory regions.\nThis unintended memory overwrite corrupts critical control data, heap structures, or stack frames, resulting in immediate exception faults, segmentation violations, or catastrophic system crashes.\nThe primary impact of this exploitation path is a denial of service condition, disrupting the availability of services hosted on the IBM i 7.6 platform.\nDepending on the specific memory layout and internal structures targeted by the write operation, more severe exploitation outcomes such as arbitrary code execution cannot be definitively ruled out theoretically, though the primary observed impact is denial of service.\nAuthentication and elevated privileges are not explicitly mandated by the nature of the vulnerability if the flawed parser or service is accessible to unauthenticated remote connections over the network."
}