
IBM i Transport Layer Security (TLS) has a vulnerability related to the selection of a less-secure algorithm during negotiation, identified as CVE-2026-4942. Vulnerability Details - CVEID: CVE-2026-4942 - Description: #IBMi could allow a remote attacker to send a specifically crafted message, potentially downgrading the Transport Layer Security (TLS) protocol to a version that is disabled in the server configuration. - CWE: CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Remediation/Fixes - 7.6 MJ09141 - 7.5 MJ09140 - 7.4 MJ09139 - 7.3 MJ09138 IBM recommends that users running unsupported versions of the affected products upgrade to a supported, fixed version.
Post summary
IBM has identified a TLS protocol downgrade vulnerability (CVE-2026-4942) in IBM i, detailing the issue and supplying patch identifiers for affected versions, while urging users to upgrade to a supported release.
