IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.
Published Sep 14, 2026
4.2
MEDIUMCVSS 3.1
EPSS 0.14%
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
Affected products
-
- Version 7.3StatusaffectedConstraints-
- Version 7.4StatusaffectedConstraints-
- Version 7.5StatusaffectedConstraints-
- Version 7.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | n/a | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now.
IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ11196 SJ11337 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196
https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337
7.5SJ11197 SJ11336 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197
https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336
7.4SJ11200 SJ11335 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200
https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335
7.3SJ11187 SJ11394 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187
https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394
IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ11377 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377 7.5SJ11376 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376 7.4SJ11375 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375 7.3SJ11374 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374
IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77765 Advisory
- https://www.ibm.com/support/pages/node/7286974 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77765 | Advisory | |
| https://www.ibm.com/support/pages/node/7286974 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.