CVE-2026-17111Patch(ibm / i)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm i systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
i

4 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · 🖥️ Enterprise Security · 11–13 August 2026 🎯 IBM patches seven SQL-related vulnerabilities in IBM i IBM has published a security bulletin covering seven vulnerabilities affecting IBM i 7.3 through 7.6. The most serious remote issue, CVE-2026-17110, carries a CVSS score of 8.8 and could allow an authenticated attacker to execute arbitrary commands and obtain sensitive information. Another flaw, CVE-2026-17111, is an SQL injection vulnerability that could allow unauthorized viewing, modification or deletion of database information. IBM says there are no workarounds and strongly recommends applying the available fixes. 🔗 Source: IBM Product Security Incident Response Team #IBM #IBMi #SQLInjection #EnterpriseSecurity #CyberSecurity

    Post summary

    IBM has released patches for seven SQL-related vulnerabilities, detailing CVE-2026-17110 and CVE-2026-17111 with CVSS scores and encouraging users to apply fixes; no PoC, exploit code, or active exploitation is reported.

    0000036
    53 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSibmi7.3--
OSibmi7.4--
OSibmi7.5--
OSibmi7.6--

Explore more