IBM Corporation
AIX
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This CVE identity is linked to the Lifecycle record IBM AIX. Use that record for publisher support phases and retirement dates.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-16821 | 28 Aug 2026 | AIX: 7.2, 7.3; PowerVM VIOS: 4.1 | A. APARS; IBM has assigned the following APARs to this problem:; AIX LevelAPARAvailability SPKEY7.2.5IJ5956608/14/2026SP13key_w_apar7.3.2IJ5956508/14/2026SP05key_w_apar7.3.3IJ5956408/14/2026SP03key_w_apar7.3.4IJ59563 08/14/2026SP02key_w_apar; VIOS LevelAPARAvailability SPKEY4.1.0IJ5956508/14/20264.1.0.50key_w_apar4.1.1IJ5956408/14/20264.1.1.30key_w_apar4.1.2IJ5956308/14/20264.1.2.20key_w_apar; B. FIXES; IBM strongly recommends addressing the vulnerability now.; AIX and VIOS fixes are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral; An LPAR reboot is required to complete the SP/FP update. On AIX, Live Update can be used to avoid a reboot.; IBM has assigned the following AIX Service Packs (SPs) and VIOS Fix Packs (FPs) as the remediation levels for the published vulnerabilities.; AIX Level Service PackAIX 7.3 TL04SP2AIX 7.3 TL03SP3AIX 7.3 TL02SP5AIX 7.2 TL05 SP13; PowerVM VIOS LevelFix PackVIOS 4.1.2 4.1.2.20VIOS 4.1.1 4.1.1.30VIOS 4.1.0 4.1.0.50; Note: These SPs/FPs are cumulative and include fixes for all previously published AIX/VIOS security vulnerabilities. They can be applied on top of any earlier affected level of the TL . | Update reference ↗ |
| CVE-2026-19783 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-19449 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-19448 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-19446 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-19442 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-19437 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18835 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18840 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18842 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18832 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18828 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18824 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18822 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18716 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-18670 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17436 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17425 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17424 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17423 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17422 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17195 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17171 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17170 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17168 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17165 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17163 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17160 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17159 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17157 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17152 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17145 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17142 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17141 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17138 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17136 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17124 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17122 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17121 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17120 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17118 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17060 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17040 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17024 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17009 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17007 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17006 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17003 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-17000 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-16997 | 20 Aug 2026 | 7.2; 7.3; 4.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.