← Vulnerability feed

Vulnerability record · CVE-2026-16937 · published 20 August 2026

CVE-2026-16937: Ibm vios improper privilege management vulnerability

Ibm · Vios

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

7.8 CVSS 3.1 High EPSS 0.14% · top 97.4% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
24 Aug 2026Last modified by NVD

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.ibm.com/support/pages/node/7283858 PatchVendor Advisory

Track CVE-2026-16937 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-56346Ibm aix vulnerabilityIBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.EPSS 1.1%10.0CVE-2010-3187Ibm aix memory buffer overflow vulnerabilityBuffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.EPSS 20%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2009-3699IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflowA stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and…EPSS 62%analysed10.0CVE-2009-3517Ibm aix vulnerabilitynfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…EPSS 4.4%10.0CVE-2006-5008Ibm aix vulnerabilityUnspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspec…EPSS 3.5%10.0CVE-2005-4272Ibm aix vulnerabilityMultiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.EPSS 9.0%10.0CVE-2005-1037Ibm aix vulnerabilityUnknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2026-16937), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.