CVE-2026-16844: IBM Aix

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Affected products

  • IBM Aix: from 7.2.5, up to and including 7.2.5.212; from 7.3.2, up to and including 7.3.2.5; from 7.3.3, up to and including 7.3.3.2; from 7.3.4, up to and including 7.3.4.1
  • IBM Vios: from 4.1.0, before 4.1.0.50 (fixed in 4.1.0.50); from 4.1.1.0, before 4.1.1.30 (fixed in 4.1.1.30); from 4.1.2.0, before 4.1.2.20 (fixed in 4.1.2.20)

Published 2026-08-19. Last modified 2026-08-24.