CVE-2026-16674
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
CVSS
8.8
High
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Aug 13, 2026 · Last modified: Aug 17, 2026 · CWE-426
0.4%EPSS · 30 days0.4%
2026-08-142026-08-19
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-168697.8 HIG—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.20hCVE-2026-748729.8 CRI38.2%
——11openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.2dCVE-2026-148757.3 HIG1.8%
——1IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.3dCVE-2026-146733.8 LOW19.2%
——6Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.2dCVE-2026-0299—9.3%
——3Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.2dCVE-2026-561747.8 HIG21.6%
——6Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.4d