IBM AIX and PowerVM VIOS hit by multiple critical vulnerabilities

Five CVEs affecting IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 were disclosed between August 19–21, 2026, exposing private keys, enabling authentication bypass, command injection, and other critical attacks. CVE-2026-15065, CVE-2026-16656, CVE-2026-16816, CVE-2026-17040, and CVE-2026-17118 collectively present severe risks to enterprise systems running these platforms.

40 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-15065: IBM AIX and PowerVM VIOS: Exposed Private Keys

stream:bsky-jetstreamother41d ago kagi ↗

CVE-2026-15065 - aix A security issue affects IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1 NIM. This means a hacker could access sensitive information and bypass security controls if they obtain an update… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec A security issue affects IBM AIX 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1 NIM.

CVE-2026-16656: IBM AIX and PowerVM VIOS Authentication Bypass

stream:bsky-jetstreamother41d ago kagi ↗

CVE-2026-16656 - aix IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 have a security issue where an attacker can access sensitive areas without permission. This could lead to unauthorized access and potentially allow… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 have a security issue where an attacker can access sensit

CVE-2026-16816: IBM AIX and PowerVM VIOS Command Injection Risk

stream:bsky-jetstreamother41d ago kagi ↗

CVE-2026-16816 - aix IBM AIX and PowerVM VIOS have a security weakness that allows a malicious user to execute unauthorized commands on the system. This could potentially lead to unauthorized access or data… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec IBM AIX and PowerVM VIOS have a security weakness that allows a malicious user to execute unauthorized commands

NVD - CVE-2026-16819

stream:bsky-jetstreamother41d ago kagi ↗

IBM AIX 7.2/7.3、PowerVM VIOS 4.1にTOCTOU競合があり、サービス拒否やデータ改ざんの可能性。 CVE-2026-16819 CVSS 7.7 | HIGH

CVE-2026-71867: Orval: Untrusted Code Execution via Schema Property Names

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-71867 - orval Orval, a tool for generating JavaScript clients, has a security issue that allows attackers to execute code in your development environment. This can happen if you're using an outdated… Too many irrelevant or confusing CVEs? Use stackflag.com #orval #orvallabs #CVE #infosec Orval, a tool for generating JavaScript clients, has a security issue that allows attackers to execute

CVE-2026-71865: Orval generates malicious JavaScript code in TypeScript clients

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-71865 - orval A security issue in Orval allows attackers to inject malicious JavaScript code when using certain query parameters. This can lead to code execution in the developer, CI, or application… Too many irrelevant or confusing CVEs? Use stackflag.com #orval #orvallabs #CVE #infosec A security issue in Orval allows attackers to inject malicious JavaScript code when using certain quer

CVE-2026-71866: Orval generates malicious JavaScript code in generated clients

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-71866 - orval Orval, a tool for generating JavaScript clients, had a bug in versions 8.19.0 to 8.21.0. This bug allowed attackers to inject malicious code into generated clients. The issue is fixed… Too many irrelevant or confusing CVEs? Use stackflag.com #orval #orvallabs #CVE #infosec Orval, a tool for generating JavaScript clients, had a bug in versions 8.19.0 to 8.21.0.

CVE-2026-72717: Orval generates JavaScript clients with unsecured code

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-72717 - orval A security risk exists in Orval's code generation for OpenAPI and Swagger specifications. If not updated to version 8.21.0 or later, malicious code can be executed when the generated… Too many irrelevant or confusing CVEs? Use stackflag.com #orval #orvallabs #CVE #infosec A security risk exists in Orval's code generation for OpenAPI and Swagger specifications.

CVE-2026-16862: IBM AIX and PowerVM VIOS Stack Buffer Overflow

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-16862 - aix IBM AIX 7.2 and 7.3, and PowerVM VIOS 4.1 are affected. This vulnerability could allow a remote attacker to take control of your system. IBM has likely released a patch or fix to address this… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec IBM AIX 7.2 and 7.3, and PowerVM VIOS 4.1 are affected. This vulnerability could allow a remote attacker

CVE-2026-45272: MyBooks (Talebook) allows attackers to run malicious code

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-45272 An attacker with admin access can inject and execute unauthorized code on your MyBooks ebook management server. This can lead to data disclosure, file modification, or disruption of the service. Upgrade to… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec MyBooks, a personal ebook management web server, has a security issue in versions 3.41.2 and earlier.

CVE-2026-62234: Grav Webhooks Allow Local File Access

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-62234 - grav Grav webhooks before version 2.0.4 allow authorized users to access local files and potentially sensitive information. This can happen when a malicious user creates a webhook with a… Too many irrelevant or confusing CVEs? Use stackflag.com #grav #getgrav #CVE #infosec Grav webhooks before version 2.0.4 allow authorized users to access local files and potentially sensitive inf

CVE-2026-11861: FreeIPA: Active Directory users can bypass FreeIPA authentication

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-11861 - red hat enterprise linux 10 FreeIPA has a flaw that allows Active Directory users to bypass authentication for certain FreeIPA services when a trust relationship is set up between the two systems.… Too many irrelevant or confusing CVEs? Use stackflag.com #redhat #CVE #infosec FreeIPA has a flaw that allows Active Directory users to bypass authentication for certain FreeIPA service

CVE-2026-66583: Forminator plugin lets attackers execute code on site

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-66583 - forminator The Forminator add‑on for WordPress, in versions up through 1.57.0, can be fooled by anyone on the internet to insert harmful data that makes the website run unwanted code.… Too many irrelevant or confusing CVEs? Use stackflag.com #forminator #wpmudev #CVE #infosec The Forminator add‑on for WordPress, in versions up through 1.57.0, can be fooled by anyone on the interne

CVE-2026-16926: IBM AIX and PowerVM allow remote file overwrite

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-16926 The AIX 7.2/7.3 operating system and PowerVM VIOS 4.1 can be tricked by a remote attacker into replacing any file on the server. This could let an attacker plant malicious code or disrupt services. Apply the… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec The AIX 7.2/7.3 operating system and PowerVM VIOS 4.1 can be tricked by a remote attacker into replacing

CVE-2026-74985: Firefox Privilege Escalation Risk in Enterprise Policies

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-74985 - firefox Firefox's Enterprise Policies component has a security weakness. This weakness could allow an attacker to gain more access than they should. To stay safe, update to the latest… Too many irrelevant or confusing CVEs? Use stackflag.com #firefox #mozilla #CVE #infosec Firefox's Enterprise Policies component has a security weakness. This weakness could allow an attacker to gai

CVE-2026-53424: Samly allows reuse of captured login token

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-53424 - samly The Samly component does not check that a SAML login token is used only once. An attacker who obtains a valid token can replay it to log in as the original user until the token… Too many irrelevant or confusing CVEs? Use stackflag.com #samly #dropbox #Hex #CVE #infosec The Samly component does not check that a SAML login token is used only once.

CVE-2026-2334: vsDesk lets admin run code through CSV import

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-2334 In vsDesk version 14.0101, an admin user can bypass the file checks when using the CSV import feature and upload any file. This can let the attacker execute code on the server through the web application. Update… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec In vsDesk version 14.0101, an admin user can bypass the file checks when using the CSV import feature

CVE-2026-63385: Libevent before 2.1.13 misinterprets URLs and headers

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-63385 Older versions of the Libevent library can treat specially coded characters in web requests incorrectly. This can cause parts of a URL to be cut off or headers to be read differently, potentially letting… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec Older versions of the Libevent library can treat specially coded characters in web requests incorrectly.

CVE-2026-19586: Omada Gateway OpenVPN allows remote command execution

stream:bsky-jetstreamother40d ago kagi ↗

CVE-2026-19586 - er7212pc v2 If your Omada gateway is set up as an OpenVPN server, an attacker on the internet can send specially crafted connection requests that run commands on the device before logging… Too many irrelevant or confusing CVEs? Use stackflag.com #er7212pcv2 #tplink #CVE #infosec If your Omada gateway is set up as an OpenVPN server, an attacker on the internet can send specially cr

CVE-2026-62834: Azure Data Factory can let attackers gain higher access

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-62834 - azure data factory Azure Data Factory may not properly verify a security check, which could let an unauthorized person raise their permission level on the service. This could allow them to view or… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec Azure Data Factory may not properly verify a security check, which could let an unauthorized person rai

CVE-2026-69836: Microsoft Entra ID can let attackers run code remotely

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-69836 - microsoft entra Microsoft Entra ID can process data that an attacker controls, which could let them run their own programs on your system over the network. This could give an… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoftentra #microsoft #CVE #infosec Microsoft Entra ID can process data that an attacker controls, which could let them run their own programs on

CVE-2026-63509: Microsoft Fabric can let attackers gain higher access

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-63509 - microsoft fabric Microsoft Fabric may allow a person who already has some access to move to a higher level of control across your network. This could let the attacker view or… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoftfabric #microsoft #CVE #infosec Microsoft Fabric may allow a person who already has some access to move to a higher level of control across

CVE-2026-65816: Azure Arc lets attackers gain higher permissions

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-65816 - azure web apps Azure Arc, the tool that links on‑premise resources to Azure, has a flaw that could let an outsider raise their access level across the network. This could expose sensitive data or… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec Azure Arc, the tool that links on‑premise resources to Azure, has a flaw that could let an outsider rais

CVE-2026-17040: IBM AIX and PowerVM VIOS could let attackers run code

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-17040 - aix The AIX operating system versions 7.2 and 7.3, along with PowerVM VIOS version 4.1, contain a flaw that can be triggered from outside the network to run unwanted programs. This could let a… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec The AIX operating system versions 7.2 and 7.3, along with PowerVM VIOS version 4.1, contain a flaw that can

CVE-2026-17136: IBM AIX and PowerVM allow attackers to run code remotely

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-17136 - aix The IBM AIX operating system versions 7.2 and 7.3, as well as the IBM PowerVM VIOS version 4.1, contain a coding mistake that could let a remote hacker make the system execute any program. This… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec The IBM AIX operating system versions 7.2 and 7.3, as well as the IBM PowerVM VIOS version 4.1, contain

CVE-2026-17145: IBM AIX and PowerVM could let remote attacker run code

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-17145 - aix The IBM AIX operating system versions 7.2 and 7.3, and the PowerVM VIOS version 4.1, have a weakness that could let someone outside your network take control of the system. This could let the… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec The IBM AIX operating system versions 7.2 and 7.3, and the PowerVM VIOS version 4.1, have a weakness that

CVE-2026-17152: IBM AIX and PowerVM VIOS could let remote code run

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-17152 - aix Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS 4.1 contain a flaw that lets specially crafted data overflow memory and run the attacker’s own programs from outside the network. If exploited,… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec Versions of IBM AIX (7.2 and 7.3) and PowerVM VIOS 4.1 contain a flaw that lets specially crafted data

CVE-2026-17422: IBM AIX and PowerVM VIOS could let local user run code

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-17422 - aix The AIX operating system versions 7.2 and 7.3, and the PowerVM VIOS version 4.1, contain a coding mistake that could let someone with access to the machine run any program they choose. This… Too many irrelevant or confusing CVEs? Use stackflag.com #aix #ibm #CVE #infosec The AIX operating system versions 7.2 and 7.3, and the PowerVM VIOS version 4.1, contain a coding mistake t

CVE-2026-55769: CloudNativePG can let a database owner gain superuser rights

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-55769 - cloudnative-pg Versions of CloudNativePG before the latest updates allow a user who owns a database to change how queries are run, letting them execute code as the system’s superuser. This can… Too many irrelevant or confusing CVEs? Use stackflag.com #cloudnativepg #CVE #infosec Versions of CloudNativePG before the latest updates allow a user who owns a database to change how quer

CVE-2026-77647: SPIP before 4.4.20 lets attackers run code

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-77647 - spip Websites using SPIP versions older than 4.4.20 can be accessed by anyone on the internet who can then cause the server to run their own programs. This happens because the software misinterprets… Too many irrelevant or confusing CVEs? Use stackflag.com #spip #CVE #infosec Websites using SPIP versions older than 4.4.20 can be accessed by anyone on the internet who can then caus

CVE-2026-76155: Datiphy Data Management Center lets attackers log in as admin

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-76155 - data management center The management console for Datiphy Data Management Center (versions 8.3.0 to 8.5.1) still accepts its factory default administrator password. Anyone who discovers this can sign… Too many irrelevant or confusing CVEs? Use stackflag.com #datiphy #CVE #infosec The management console for Datiphy Data Management Center (versions 8.3.0 to 8.5.1) still accepts its

CVE-2026-76156: Datiphy Data Management Center lets admin run any system command

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-76156 - data management center Versions of Datiphy Data Management Center from 8.3.0 to 8.5.1 let a signed‑in administrator run any command on the server, giving them full control over the machine. This… Too many irrelevant or confusing CVEs? Use stackflag.com #datiphy #CVE #infosec Versions of Datiphy Data Management Center from 8.3.0 to 8.5.1 let a signed‑in administrator run any comman

CVE-2026-63337: RabbitMQ Java Client: Unvalidated Class Loading Enables Arbitrary Code Execution

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-63337 - rabbitmq-java-client The RabbitMQ Java client's JSON-RPC tools can load arbitrary classes from untrusted messages, potentially allowing an attacker to execute malicious code in the victim's… Too many irrelevant or confusing CVEs? Use stackflag.com #rabbitmq #Java #CVE #infosec The RabbitMQ Java client's JSON-RPC tools can load arbitrary classes from untrusted messages, potentially

CVE-2026-23933: Zabbix 7.4: Unauthorized access via forged session cookies

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-23933 - zabbix Zabbix version 7.4 uses a cryptographic key to sign the cookies that keep a user logged into the web interface. Because the key can be guessed or extracted, an… Too many irrelevant or confusing CVEs? Use stackflag.com #zabbix #canonical #UbuntuPro1404LTS #CVE #infosec Zabbix 7.4 may allow unauthorized access if an attacker knows a hardcoded session key.

CVE-2026-62867: Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument inject...

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-62867 - incus A security issue affects incus (Debian). The advisory does not describe the issue in detail. Check the linked advisory for the fixed version and details. Too many irrelevant or confusing CVEs? Use stackflag.com #incus #debian #Debian13 #CVE #infosec Incus is a system container and virtual machine manager.

CVE-2026-77806: SPIP versions before 4.4.21 let attackers run code

stream:bsky-jetstreamother39d ago kagi ↗

CVE-2026-77806 - spip Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwanted programs on the server. The problem comes from a special HTTP header that the software… Too many irrelevant or confusing CVEs? Use stackflag.com #spip #CVE #infosec Websites using SPIP older than version 4.4.21 can be tricked by anyone on the internet into running unwa

CVE-2026-59989: Phalcon Volt templates can run attacker code

stream:bsky-jetstreamother38d ago kagi ↗

CVE-2026-59989 - cphalcon If a website uses Phalcon's Volt template engine and allows users to influence the text passed to the join filter, the engine can insert that text directly into generated… Too many irrelevant or confusing CVEs? Use stackflag.com #cphalcon #phalcon #composer #CVE #infosec If a website uses Phalcon's Volt template engine and allows users to influence the text passed to the