The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-16687 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the F... read CVE-2026-16687
Published: August 19, 2026; 3:17:10 PM -0400 -
CVE-2026-16922 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.
Published: August 20, 2026; 11:17:28 AM -0400 -
CVE-2026-16923 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Published: August 20, 2026; 11:17:28 AM -0400V3.1: 7.8 HIGH
-
CVE-2026-16924 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
Published: August 20, 2026; 11:17:28 AM -0400 -
CVE-2026-16925 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.
Published: August 20, 2026; 11:17:28 AM -0400V3.1: 7.8 HIGH
-
CVE-2026-16927 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition.
Published: August 20, 2026; 11:17:29 AM -0400V3.1: 7.0 HIGH
-
CVE-2026-16928 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
Published: August 20, 2026; 11:17:29 AM -0400 -
CVE-2026-16932 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable.
Published: August 20, 2026; 11:17:29 AM -0400 -
CVE-2026-16930 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/... read CVE-2026-16930
Published: August 19, 2026; 3:17:10 PM -0400 -
CVE-2026-16989 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.
Published: August 20, 2026; 6:17:10 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-21962 - Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that ar... read CVE-2026-21962
Published: January 20, 2026; 5:15:59 PM -0500 -
CVE-2026-16991 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
Published: August 20, 2026; 6:17:10 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-17015 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
Published: August 19, 2026; 5:16:54 PM -0400V3.1: 8.1 HIGH
-
CVE-2026-18102 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.
Published: August 19, 2026; 5:16:54 PM -0400V3.1: 4.3 MEDIUM
-
CVE-2025-36254 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cau... read CVE-2025-36254
Published: August 19, 2026; 6:16:36 PM -0400 -
CVE-2025-36398 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
Published: August 19, 2026; 6:16:36 PM -0400 -
CVE-2026-76398 - In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerabilit... read CVE-2026-76398
Published: August 19, 2026; 6:17:26 PM -0400 -
CVE-2026-76399 - In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ... read CVE-2026-76399
Published: August 19, 2026; 6:17:26 PM -0400V3.1: 8.1 HIGH
-
CVE-2025-36255 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.
Published: August 19, 2026; 6:16:36 PM -0400V3.1: 8.8 HIGH
-
CVE-2026-76400 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splu... read CVE-2026-76400
Published: August 19, 2026; 6:17:26 PM -0400