IBM has released security patches for a series of vulnerabilities in IBM AIX and PowerVM VIOS, published on August 15, 2026. The patch addresses seven critical CVEs, including three command injection flaws and multiple memory-related bugs, all with CVSS scores of 9.9 and 9.8. While none of these vulnerabilities have been reported as actively exploited, they pose significant risks to systems running core workloads in sectors such as banking and telecommunications.
Users are advised to apply the security updates promptly as these flaws can allow remote code execution, some requiring no authentication. The affected AIX versions include 7.2, 7.3, and PowerVM VIOS 4.1.