IBM Patches 191 Vulnerabilities in AIX and PowerVM VIOS Including Critical Remote Command Execution Flaws
IBM has released security updates to address a large number of vulnerabilities in its AIX UNIX operating system and the PowerVM VIOS virtual I/O server. The issues were detailed in an advisory published on August 15 and include both internally developed code and third-party components.
In total, the company resolved 191 CVEs. According to the Common Vulnerability Scoring System, 35 vulnerabilities carry base scores of 9.0 or higher. Three OS command injection flaws stand out with a score of 9.9: CVE-2026-18835, CVE-2026-16816, and CVE-2026-15068. An additional 23 issues received a score of 9.8.
Affected Products and Fixes
The following AIX releases contain the fixes:
- AIX 7.3 TL04 SP2
- AIX 7.3 TL03 SP3
- AIX 7.3 TL02 SP5
- AIX 7.2 TL05 SP13
For PowerVM VIOS, IBM released versions 4.1.2.20, 4.1.1.30, and 4.1.0.50.
Full List of Addressed CVEs
The complete list of resolved vulnerabilities includes:
- CVE-2025-12817, CVE-2025-12818, CVE-2025-15649, CVE-2026-2003 through CVE-2026-2006, CVE-2026-6472 through CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6637, CVE-2026-8368, CVE-2026-8400, CVE-2026-8829, CVE-2026-12087, CVE-2026-14970, CVE-2026-15061, CVE-2026-15065, CVE-2026-15068, CVE-2026-15078, CVE-2026-16243, CVE-2026-16439, CVE-2026-16441, CVE-2026-16656, CVE-2026-16686, CVE-2026-16690, CVE-2026-16703, CVE-2026-16706, CVE-2026-16814, CVE-2026-16816 through CVE-2026-16819, CVE-2026-16821 through CVE-2026-16825, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16833, CVE-2026-16834, CVE-2026-16836 through CVE-2026-16842, CVE-2026-16844 through CVE-2026-16852, CVE-2026-16855, CVE-2026-16857, CVE-2026-16862, CVE-2026-16864 through CVE-2026-16866, CVE-2026-16869, CVE-2026-16872 through CVE-2026-16875, CVE-2026-16877, CVE-2026-16882, CVE-2026-16883, CVE-2026-16885, CVE-2026-16886, CVE-2026-16888, CVE-2026-16890, CVE-2026-16891, CVE-2026-16894, CVE-2026-16897, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16911, CVE-2026-16913, CVE-2026-16914, CVE-2026-16917, CVE-2026-16919, CVE-2026-16922 through CVE-2026-16928, CVE-2026-16932, CVE-2026-16934 through CVE-2026-16937, CVE-2026-16943 through CVE-2026-16946, CVE-2026-16951, CVE-2026-16952, CVE-2026-16958, CVE-2026-16964, CVE-2026-16972, CVE-2026-16973, CVE-2026-16980, CVE-2026-16989, CVE-2026-16991, CVE-2026-16996, CVE-2026-16997, CVE-2026-17000, CVE-2026-17003, CVE-2026-17006, CVE-2026-17007, CVE-2026-17009, CVE-2026-17024, CVE-2026-17040, CVE-2026-17060, CVE-2026-17118, CVE-2026-17120 through CVE-2026-17122, CVE-2026-17124, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17159, CVE-2026-17160, CVE-2026-17163, CVE-2026-17165, CVE-2026-17168, CVE-2026-17170, CVE-2026-17171, CVE-2026-17195, CVE-2026-17422 through CVE-2026-17425, CVE-2026-17436, CVE-2026-18670, CVE-2026-18716, CVE-2026-18822, CVE-2026-18824, CVE-2026-18828, CVE-2026-18832, CVE-2026-18835, CVE-2026-18840, CVE-2026-18842, CVE-2026-19437, CVE-2026-19442, CVE-2026-19446, CVE-2026-19448, CVE-2026-19449, CVE-2026-19653, CVE-2026-19783, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-41254, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057 through CVE-2026-47059, CVE-2026-47063, CVE-2026-48959, CVE-2026-48962, CVE-2026-59995 through CVE-2026-59997, CVE-2026-59999 through CVE-2026-60002, CVE-2026-60147
Administrators are advised to apply the listed updates as soon as possible to mitigate the highest-risk issues.
Related articles
Browser Built on Mistakes: How Real-World Attacks Shaped Modern Browser Defenses
Browser security features such as process isolation, sandboxing, and restrictions on code execution were not designed in isolation but evolved directly in response to concrete attacks over more than a decade. Early threats like malicious Flash advertisements in 2015 demonstrated how a single compromised banner could compromise an entire system, prompting the industry to phase out plugins entirely. Later discoveries, including the Spectre vulnerability, forced browsers to implement stricter site isolation and timing-attack mitigations that remain in place today. Session hijacking and malicious browser extensions further drove the adoption of stronger cookie protections and permission models. BI.ZONE analysts trace this history through specific incidents to show why current architectures prioritize separation of sites into distinct processes. The resulting design reduces the blast radius of any single exploit and continues to adapt as new attack classes emerge.
cKEV Index Launches to Prioritize Vulnerabilities as AI Accelerates Exploit Development
CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities ranked by the Urgent Patch Score (UPS) methodology. The index incorporates timelines of events such as exploit publication, proof-of-concept releases, and confirmed attacks to help organizations prioritize patching under resource constraints. It addresses the growing gap between rapid AI-assisted vulnerability discovery and slower remediation processes at both vendors and customers. Examples from Anthropic reports highlight how threat actors used AI agents for reconnaissance, code analysis, and exploit development against Android apps and web applications. Microsoft and Oracle have publicly linked increased vulnerability findings and larger patch releases to AI tooling. The UPS framework defines progressive phases from Radar to Emergency/IR, allowing teams to act on strong signals without waiting for full confirmation. An open version of the catalog is now available with detailed event histories for Urgent Patch and Emergency stages.
Apache HTTP Server 2.4.69 Patches 20 Vulnerabilities Including CVSS 9.8 Issues
The Apache HTTP Server development team released version 2.4.69 on October 1, 2026, addressing a total of 20 vulnerabilities. While the Apache Security Team assessed most issues as moderate or low in impact, several vulnerabilities received CVSS base scores as high as 9.8. The update includes fixes for stack-based buffer overflows, use-after-free conditions, and out-of-bounds writes affecting multiple modules. No vulnerabilities were rated Critical or Important by the developers, with five classified as Moderate and fifteen as Low. Specific fixes cover the mod_vhost_alias, mod_http2, mod_dav, and mod_dav_fs modules, along with Windows-specific path handling problems.
BrokenPipe PoC Exploits Steam Client Service for Silent SYSTEM Privilege Escalation on Windows
A new proof-of-concept named BrokenPipe demonstrates how a standard Windows user can escalate privileges to NT AUTHORITY\SYSTEM through the Steam Client Service without requiring administrator credentials or triggering a UAC prompt. The vulnerability stems from insufficient signature validation in VDF installation scripts processed by steamservice.exe, allowing an attacker to control the execution path of a malicious script. The issue affects Steam version 10.96.30.42 on both Windows 10 and Windows 11, though no public CVE has been assigned yet. Valve was notified of the flaw in March, several months prior to public disclosure. The attack is strictly local and requires initial code execution under a standard user account, making it relevant for shared or corporate environments. Security teams are advised to inventory Steam installations, apply application allowlisting, and monitor for anomalous SYSTEM-level processes linked to the service while awaiting an official patch.