IBM Patches 191 Vulnerabilities in AIX and PowerVM VIOS Including Critical Remote Command Execution Flaws
IBM has released security updates to address a large number of vulnerabilities in its AIX UNIX operating system and the PowerVM VIOS virtual I/O server. The issues were detailed in an advisory published on August 15 and include both internally developed code and third-party components.
In total, the company resolved 191 CVEs. According to the Common Vulnerability Scoring System, 35 vulnerabilities carry base scores of 9.0 or higher. Three OS command injection flaws stand out with a score of 9.9: CVE-2026-18835, CVE-2026-16816, and CVE-2026-15068. An additional 23 issues received a score of 9.8.
Affected Products and Fixes
The following AIX releases contain the fixes:
- AIX 7.3 TL04 SP2
- AIX 7.3 TL03 SP3
- AIX 7.3 TL02 SP5
- AIX 7.2 TL05 SP13
For PowerVM VIOS, IBM released versions 4.1.2.20, 4.1.1.30, and 4.1.0.50.
Full List of Addressed CVEs
The complete list of resolved vulnerabilities includes:
- CVE-2025-12817, CVE-2025-12818, CVE-2025-15649, CVE-2026-2003 through CVE-2026-2006, CVE-2026-6472 through CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6637, CVE-2026-8368, CVE-2026-8400, CVE-2026-8829, CVE-2026-12087, CVE-2026-14970, CVE-2026-15061, CVE-2026-15065, CVE-2026-15068, CVE-2026-15078, CVE-2026-16243, CVE-2026-16439, CVE-2026-16441, CVE-2026-16656, CVE-2026-16686, CVE-2026-16690, CVE-2026-16703, CVE-2026-16706, CVE-2026-16814, CVE-2026-16816 through CVE-2026-16819, CVE-2026-16821 through CVE-2026-16825, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16833, CVE-2026-16834, CVE-2026-16836 through CVE-2026-16842, CVE-2026-16844 through CVE-2026-16852, CVE-2026-16855, CVE-2026-16857, CVE-2026-16862, CVE-2026-16864 through CVE-2026-16866, CVE-2026-16869, CVE-2026-16872 through CVE-2026-16875, CVE-2026-16877, CVE-2026-16882, CVE-2026-16883, CVE-2026-16885, CVE-2026-16886, CVE-2026-16888, CVE-2026-16890, CVE-2026-16891, CVE-2026-16894, CVE-2026-16897, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16911, CVE-2026-16913, CVE-2026-16914, CVE-2026-16917, CVE-2026-16919, CVE-2026-16922 through CVE-2026-16928, CVE-2026-16932, CVE-2026-16934 through CVE-2026-16937, CVE-2026-16943 through CVE-2026-16946, CVE-2026-16951, CVE-2026-16952, CVE-2026-16958, CVE-2026-16964, CVE-2026-16972, CVE-2026-16973, CVE-2026-16980, CVE-2026-16989, CVE-2026-16991, CVE-2026-16996, CVE-2026-16997, CVE-2026-17000, CVE-2026-17003, CVE-2026-17006, CVE-2026-17007, CVE-2026-17009, CVE-2026-17024, CVE-2026-17040, CVE-2026-17060, CVE-2026-17118, CVE-2026-17120 through CVE-2026-17122, CVE-2026-17124, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17159, CVE-2026-17160, CVE-2026-17163, CVE-2026-17165, CVE-2026-17168, CVE-2026-17170, CVE-2026-17171, CVE-2026-17195, CVE-2026-17422 through CVE-2026-17425, CVE-2026-17436, CVE-2026-18670, CVE-2026-18716, CVE-2026-18822, CVE-2026-18824, CVE-2026-18828, CVE-2026-18832, CVE-2026-18835, CVE-2026-18840, CVE-2026-18842, CVE-2026-19437, CVE-2026-19442, CVE-2026-19446, CVE-2026-19448, CVE-2026-19449, CVE-2026-19653, CVE-2026-19783, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-41254, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057 through CVE-2026-47059, CVE-2026-47063, CVE-2026-48959, CVE-2026-48962, CVE-2026-59995 through CVE-2026-59997, CVE-2026-59999 through CVE-2026-60002, CVE-2026-60147
Administrators are advised to apply the listed updates as soon as possible to mitigate the highest-risk issues.
Related articles
CISA Adds Zimbra Collaboration Suite CVE-2026-73570 to KEV Catalog After Confirmed Exploitation
US authorities have issued a warning about active exploitation of a vulnerability in the Zimbra Collaboration Suite. CISA added the OS command injection flaw CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on August 21, 2026, marking the fifth such entry for the year. The issue resides in the SNMP monitoring component and allows unauthenticated attackers to execute arbitrary operating system commands with Zimbra user privileges when SNMP notifications are enabled. MITRE rated the vulnerability 8.9 on CVSS v3.1, classifying it as High severity. Federal agencies must apply mitigations by August 24, while all organizations using the product are urged to prioritize patching to prevent further abuse.
Vulnaware Bridges Vulnerability Scanners and ITSM Systems to Improve Critical Flaw Prioritization
A new open-source tool called Vulnaware has been developed to address the persistent gap between vulnerability discovery and remediation in enterprise environments. The project focuses on intelligent prioritization rather than attempting to fix every reported CVE, recognizing that fewer than 10 percent of published vulnerabilities are ever exploited. It integrates outputs from MaxPatrol VM, Nessus Pro, and Greenbone/OpenVAS, then applies scoring based on CISA KEV catalog presence, public exploit availability from Vulncheck feeds, and trend data. Prioritized issues are automatically converted into tickets in Jira Service Management, GLPI, Znuny, and osTicket, while also delivering alerts via Telegram and email. The approach aligns with the updated CISA BOD 26-04 framework that replaced flat 15- and 25-day deadlines with risk-based timelines of 3, 14, or 60 days. By treating vulnerability remediation as a managed change or service request under ITIL4 principles, Vulnaware ensures that critical issues reach the correct engineering teams with proper SLA tracking.
PostgreSQL Releases Security Update Fixing 28 Vulnerabilities and Over 110 Bugs
The PostgreSQL development team issued a major security update on August 13, 2026, addressing 28 vulnerabilities along with more than 110 bugs. While no issues reached a CVSSv3.1 base score of 9.0 or higher, 18 vulnerabilities scored 7.0 or above, with 14 rated at 8.8. Several flaws enable arbitrary code execution, including heap buffer overflows in regular expression processing and the to_char function. Additional fixes cover heap buffer overflows in pg_stat_statements and pg_dump, type confusion issues, and an SQL injection vulnerability. The update resolves specific CVEs such as CVE-2026-14664, CVE-2026-14669, CVE-2026-14670, CVE-2026-16238, CVE-2026-16239, and CVE-2026-15741.
Vulnerability in Docker go-archive Library Allows File Creation and Overwrite Outside Target Directory
A vulnerability has been identified in the go-archive archive processing library used by Docker and related software. The flaw, tracked as CVE-2026-17106, affects the Unpack, UnpackLayer, and Untar functions and permits files to be created or overwritten outside the intended extraction directory. The issue stems from a mismatch between the path string validated by the code and the actual path resolved by the operating system. Docker rated the vulnerability 7.1 under CVSS v4.0 and classified it as High severity. A proof-of-concept exploit has already been published for macOS and Linux. The fix was implemented in go-archive 0.3.0 and shipped in Docker Engine 29.7.0, Docker CLI 29.7.0, and Docker Desktop 4.86.0.