CVE-2026-17083Disclosure(ibm / i)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
i

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-13: 2Technical Details · 2026-08-13: 208-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • transilienceai@transilienceai
    Disclosure

    IBM i ACS users: check your exposure. CVE-2026-17083 is a CVSS 8.8 RCE affecting IBM i Access Client Solutions 1.1.5.0–1.1.9.12. • Network exploitable • Low privileges required • No user interaction • Exposure depends on the IBM i Navigator listener configuration Prioritize affected deployments. Full Advisory: https://app.transilience.cloud/run-history/3d44c4d9-d444-486e-b8b7-3face4717a55?file=reports%2Fproducts%2FMicrosoft_Windows_Deployment_Services_TFTP_Server_RCE__CVE-2026-62893__microsoft_windows_deployment_services_tftp_server_rce__cve-2026-62893__report.pdf

    Post summary

    IBM i Access Client Solutions users are urged to assess exposure to CVE-2026-17083, a network‑exploitable RCE with a CVSS score of 8.8 that requires low privileges. No PoC, exploit, or patch is mentioned and no active exploitation is reported.

    0000071
    329 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 IBM i Mass Patch Day — 9 CVEs, CVSS 9.9 PEAK CVE-2026-16860 (9.9): Uncontrolled search path RCE CVE-2026-17083 (9.8): Debug Server RCE (unauthenticated) → http://threataft.com/articles/ibm-i-mass-patch-day-august-2026-9-cves #cybersecurity #infosec #IBMi #AS400 #PatchTuesday #ERPy #ThreatIntel

    Post summary

    The tweet announces IBM i Mass Patch Day, listing two high‑severity RCE CVEs with associated CVSS scores, but provides no PoC, exploit code, or patch details beyond a general article link.

    0000078
    36 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSibmi7.3--
OSibmi7.4--
OSibmi7.5--
OSibmi7.6--

Explore more