CVE-2026-16860
Critical · CVSS 9.9- CVSS
- 9.9
- nvd
- EPSS
- 0.46%
- 38th pct
- KEV
- No
- Class
- other
- CWE-427
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
References
Status: profiled · ingested 2026-08-13T18:00:50.000Z