The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-17110 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
Published: August 12, 2026; 2:17:25 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-17218 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Published: August 12, 2026; 2:17:25 PM -0400 -
CVE-2026-17222 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400 -
CVE-2026-17248 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17266 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17268 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of a session token.
Published: August 12, 2026; 2:17:26 PM -0400 -
CVE-2026-17271 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-17276 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 9.9 CRITICAL
-
CVE-2026-18713 - IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
Published: August 12, 2026; 2:17:28 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-18669 - IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Published: August 12, 2026; 2:17:28 PM -0400 -
CVE-2026-18250 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
Published: August 12, 2026; 2:17:28 PM -0400V3.1: 5.0 MEDIUM
-
CVE-2026-18235 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
Published: August 12, 2026; 2:17:28 PM -0400 -
CVE-2026-17420 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.
Published: August 12, 2026; 2:17:27 PM -0400 -
CVE-2026-17419 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-17418 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
Published: August 12, 2026; 2:17:26 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-58484 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes ... read CVE-2026-58484
Published: July 20, 2026; 1:18:16 PM -0400 -
CVE-2026-58482 - Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate` uses to... read CVE-2026-58482
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-58481 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox base suc... read CVE-2026-58481
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-58414 - Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If... read CVE-2026-58414
Published: July 20, 2026; 1:18:15 PM -0400 -
CVE-2026-18477 - A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the sys... read CVE-2026-18477
Published: August 03, 2026; 1:16:33 PM -0400