CVE-2026-17218PoC(ibm / i)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for ibm i systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
i

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Technical Details · 2026-08-13: 108-1208-13
Signal classification2 categories
PoC
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-121
PoC1
2026-08-131
Disclosure1
Full discourse2 posts
  • Aretiq.AI@AretiqAI
    PoC

    ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit available 🔴 CRITICAL: CVE-2026-73263 (prowler-cloud/prowler) AAS 12.7 — exploit available 🔴 CRITICAL: CVE-2026-73300 (budibase/budibase) AAS 12.7 — exploit available + 2 more CRITICAL 30 vulnerabilities — CRITICAL: 7, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-08-12/

    Post summary

    The bulletin announces 30 critical vulnerabilities, noting PoC or exploit code availability for several CVEs, but offers no evidence of active exploitation or available patches.

    00094526
    232 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-17218 Arbitrary Code Execution in IBM i 7.6, 7.5, 7.4, and 7.3 via Out-of-Bounds Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-17218

    Post summary

    Vulnerability CVE-2026-17218 is announced as an arbitrary code execution flaw via an out‑of‑bounds write in IBM i, but no PoC, exploit code, active exploitation, patches, or debunking information is provided.

    00000127
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmi---

Explore more