
Security Bulletin: IBM i is Affected by a Denial of Service Vulnerability [CVE-2026-6936] Security Bulletin CVEID: CVE-2026-6936 DESCRIPTION: IBM i is vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An authenticated attacker could exploit this vulnerability by compiling specially crafted source code containing a specific combination of statements. CWE: CWE-674: Uncontrolled Recursion CVSS Source: IBM CVSS Base score: 6.5 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) IBM i Release Fixing PTF 7.6 MJ09365 7.5 MJ09335 7.4 MJ09334 7.3 MJ09332
Post summary
IBM i is affected by a denial‑of‑service vulnerability (CVE‑2026‑6936) caused by uncontrolled recursion in the ILE compiler; IBM released fix packages (PTFs) for affected versions and provided detailed technical information, but no proof of exploit or active wild usage is reported.
