CVE-2026-6936Patch(ibm / i)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm i systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
i

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 105-13
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Pete Massiello@petem59
    Patch

    Security Bulletin: IBM i is Affected by a Denial of Service Vulnerability [CVE-2026-6936] Security Bulletin CVEID:   CVE-2026-6936 DESCRIPTION:   IBM i is vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements. CWE:   CWE-674: Uncontrolled Recursion CVSS Source:   IBM CVSS Base score:   6.5 CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) IBM i Release Fixing PTF 7.6 MJ09365 7.5 MJ09335 7.4 MJ09334 7.3 MJ09332

    Post summary

    IBM i is affected by a denial‑of‑service vulnerability (CVE‑2026‑6936) caused by uncontrolled recursion in the ILE compiler; IBM released fix packages (PTFs) for affected versions and provided detailed technical information, but no proof of exploit or active wild usage is reported.

    10011146
    1.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appibmi---
OSibmi---

Explore more