IBM i PTF Guide, Volume 28, Number 28: A Crazy Number of Security Vulnerability Patches
August 17, 2026 Doug Bidwell
It looks like 28 is not your lucky number if you are an IBM i shop. The reason why is that in Volume 28 and Number 28 of the IBM i PTF Guide, Big Blue has released a truly amazing number of security vulnerabilities and patches for the IBM i platform. We counted 40 security vulnerabilities, some of which are still awaiting patches, plus 22 High Impact/Pervasive (HIPER) patches for firmware on Power9, Power10, and Power11 systems. But a few items before we dive into that.
First: The System Planning Tool, version 6.26.223.0, is now available for download at https://www.ibm.com/support/pages/node/632531. This is a minor announce and maintenance release of SPT that contains the following: Fixed CPW values for 9242-21B and 9242-21T servers.
And just to repeat this in case you missed it: There are IBM i Access – ACS Updates, with Version: 1.1.9.14 released in August 2026 available at https://www.ibm.com/support/pages/ibm-i-access-acs-updates. All prior versions are vulnerable to:
- Arbitrary code execution on Windows when installed for all users due to publicly writeable directory and configuration file.
- Injection of rogue certificate authority due to publicly writeable truststore.
- Zip slip path traversal exploit when importing a configuration.
- Versions 1.1.8.3 through 1.1.9.13 are vulnerable to downloading unverified product code when configured to update from an IBM i.
- The sample scripts in Documentation\Sample_Scripts\Linux_Mac_Other are vulnerable to arbitrary code execution via maliciously crafted input parameters.
And finally: SMS Notifications for IBM Support are now available in selected regions around the globe. IBM is expanding the ways you can receive important updates related to your support cases and field service activities. In addition to existing digital channels such as email, we are introducing SMS (text message) notifications to help ensure you stay informed in real time. This feature is being introduced gradually, with more capabilities and country coverage to follow. What’s Available Today: Onsite Technician Arrival Notifications. SMS notification support is initially available in the following countries: United States, Canada, Chile, and Mexico.
Now let’s start with the security bulletins and then move onto the HIPER firmware patches. We are not going to be our usual chatty selves here with the text and the formatting because we are just trying to get the data to you. Here we go! Hold on to your hardhat!
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension, at https://www.ibm.com/support/pages/node/7283285?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-JV1 PTF Number(s)
7.6 SJ11036
SJ11072
SJ11082
SJ11088
7.5 SJ11068
SJ11073
SJ11070
SJ11077
SJ11087
7.4 SJ11071
SJ11069
SJ11076
SJ11086
7.3 SJ11067
SJ11075
SJ11085
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty, at https://www.ibm.com/support/pages/node/7283286?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions
IBM i Release 5770-SS1 Option 3 PTF Number(s)
7.6 SJ10874
SJ11023
7.5 SJ10875
SJ11024
7.4 SJ10876
SJ11025
7.3 SJ10877
SJ11026
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol, at https://www.ibm.com/support/pages/node/7283291?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-TC1 PTF Number(s)
7.6 SJ11061
SJ11131
7.5 SJ11074
SJ11129
7.4 SJ11083
SJ11127
7.3 SJ11084
SJ11123
Security Bulletin: IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime, at https://www.ibm.com/support/pages/node/7283283?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSSKWKM&mynp=OCSSB23CE&mynp=OCSS9QQS&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSSKWKM-OCSSB23CE-OCSS9QQS-_-E. Affected Products and Versions:
IBM i Release 5770-JV1 PTF Number(s)
7.6 SJ11037
SJ11013
SJ11065
SJ11078
7.5 SJ10990
SJ11014
SJ11042
SJ11066
SJ11080
7.4 SJ11016
SJ11041
SJ11064
SJ11081
7.3 SJ11040
SJ11063
SJ11079
Security Bulletin: IBM i is Affected By An Improper Validation Vulnerability [CVE-2026-17498], at https://www.ibm.com/support/pages/node/7283479?myns=swgother&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-OCSWG60-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10855
7.5 SJ10856
7.4 SJ10857
7.3 SJ10858
Security Bulletin: IBM Db2 Mirror for i is affected by multiple vulnerabilities, at https://www.ibm.com/support/pages/node/7283359?myns=swgother&mynp=OCSSLLPF&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSSLLPF-OCSWG60-_-E. Affected Products and Versions:
IBM i Release 5770-DBM PTF Numbers
7.6 SJ10948
7.5 SJ10961
7.4 SJ10947
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service, at https://www.ibm.com/support/pages/node/7283293?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ11094
7.5 SJ11093
7.4 SJ11095
7.3 SJ11096
Security Bulletin: IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM [CVE-2026-17078], at https://www.ibm.com/support/pages/node/7283571?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Patches are:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10836
7.5 SJ10837
7.4 SJ10838
7.3 SJ10839
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in DRDA/DDM (multiple CVEs), at https://www.ibm.com/support/pages/node/7283572?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10848
7.5 SJ10849
7.4 SJ10850
7.3 SJ10851
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager, at https://www.ibm.com/support/pages/node/7283569?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 Option 34 PTF Number(s)
7.6 SJ10907
7.5 SJ10906
7.4 SJ10905
7.3 SJ10904
Security Bulletin: IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP [CVE-2026-17438], at https://www.ibm.com/support/pages/node/7283273?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10919
7.5 SJ10989
7.4 SJ10991
7.3 SJ10992
Security Bulletin: IBM i is Affected By A Prvilege Escalation Vulnerability [CVE-2026-18509], at https://www.ibm.com/support/pages/node/7283279?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10887
7.5 SJ10888
7.4 SJ10890
7.3 SJ10891
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Host Servers, at https://www.ibm.com/support/pages/node/7283578?myns=swgother&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-OCSWG60-_-E.
Host Servers:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ11101
SJ11097
7.5 SJ11102
SJ11098
7.4 SJ11103
SJ11099
7.3 SJ11104
SJ11100
Debug Server:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10899
Telnet:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ11022
DRDA/DDM
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10848
Security Bulletin: IBM i is Affected By An Improper Management Vulnerability in HTTP Server [CVE-2026-18071], at https://www.ibm.com/support/pages/node/7283579?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-DG1 PTF Number(s)
7.6 SJ11135
7.5 SJ11136
7.4 SJ11137
7.3 SJ11138
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in NetServer, at https://www.ibm.com/support/pages/node/7283573?myns=swgother&mynp=OCSWG60&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mynp=OCSSTS2D&mync=E&cm_sp=swgother-_-OCSWG60-OCSS9QQS-OCSSB23CE-OCSSKWKM-OCSSTS2D-_-E. Affected Products and Versions:
IBM i Release 5770-999 PTF Number(s)
7.6 MJ10939
7.5 MJ10938
7.4 MJ10937
7.3 MJ10936
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in SQL, at https://www.ibm.com/support/pages/node/7283289?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10867
7.5 SJ10868
7.4 SJ10869
7.3 SJ10870
Security Bulletin: IBM i is Affected By A Denial of Service Vulnerability DST/SST [CVE-2026-16887], at https://www.ibm.com/support/pages/node/7283319?myns=swgother&mynp=OCSWG60&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-999 PTF Number(s)
7.6 MJ10909
Security Bulletin: IBM i is Affected By Remote Code Execution Vulnerability [CVE-2026-16860], at https://www.ibm.com/support/pages/node/7283282?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10879
7.5 SJ10880
7.4 SJ10881
7.3 SJ10882
Security Bulletin: IBM Db2 Mirror for i is vulnerable to OS command injection [CVE-2026-16956], at https://www.ibm.com/support/pages/node/7283281?myns=swgother&mynp=OCSSLLPF&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSSLLPF-OCSWG60-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Numbers
7.6 SJ10951
7.5 SJ10954
7.4 SJ10957
Security Bulletin: IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL [CVE-2026-16722], at https://www.ibm.com/support/pages/node/7283299?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10823
7.5 SJ10822
7.4 SJ10821
7.3 SJ10820
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Domain Name System, at https://www.ibm.com/support/pages/node/7283284?myns=swgother&mynp=OCSWG60&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 Option 33 PTF Number(s)
7.6 SJ10931
7.5 SJ11010
Security Bulletin: IBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon [CVE-2026-17445], at https://www.ibm.com/support/pages/node/7283274?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10878
7.5 SJ10917
7.4 SJ10934
7.3 SJ10935
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in the Debug Server, at https://www.ibm.com/support/pages/node/7283276?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10899
7.5 SJ10903
7.4 SJ10915
7.3 SJ10916
Security Bulletin: IBM i is Affected By Out-of-Bounds Read Vulnerability [CVE-2026-16863], at https://www.ibm.com/support/pages/node/7283280?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-999 PTF Number(s)
7.6 MJ10974
7.5 MJ10973
7.4 MJ10972
7.3 MJ10971
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Navigator for i, at https://www.ibm.com/support/pages/node/7283292?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 Option 3 PTF Number(s)
7.6 SJ10887
7.5 SJ10888
7.4 SJ10890
7.3 SJ10891
Security Bulletin: IBM i is Affected By a Denial of Service in HTTP Server [CVE-2026-17272], at https://www.ibm.com/support/pages/node/7283295?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-DG1 PTF Number(s)
7.6 SJ10845
7.5 SJ10844
7.4 SJ10843
7.3 SJ10842
Security Bulletin: IBM i is Affected By Remote Code Execution Vulnerabilities [CVE-2026-17642, CVE-2026-17417], at https://www.ibm.com/support/pages/node/7283275?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10968
7.5 SJ10967
7.4 SJ10966
7.3 SJ10964
Security Bulletin: IBM i is Affected By A Denial of Service Vulnerability [CVE-2026-16931], at https://www.ibm.com/support/pages/node/7283288?myns=swgother&mynp=OCSWG60&mynp=OCSSB23CE&mynp=OCSSKWKM&mynp=OCSSTS2D&mynp=OCSS9QQS&mync=E&cm_sp=swgother-_-OCSWG60-OCSSB23CE-OCSSKWKM-OCSSTS2D-OCSS9QQS-_-E. Affected Products and Versions:
IBM i Release 5770-999 PTF Number(s)
7.6 MJ10911
7.5 MJ10912
7.4 MJ10913
7.3 MJ10914
Security Bulletin: IBM i is Affected By An Improper Validation Vulnerability in PASE [CVE-2026-16987], at https://www.ibm.com/support/pages/node/7283296?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 Option 33 PTF Number(s)
7.6 SJ10846
7.5 SJ10847
7.4 SJ10852
7.3 SJ10854
Security Bulletin: IBM i is Affected By A Remote Code Execution Vulnerability [CVE-2026-16975], at https://www.ibm.com/support/pages/node/7283300?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-999 PTF Number(s)
7.6 MJ11019
7.5 MJ11050
7.4 MJ11051
7.3 MJ11052
Security Bulletin: IBM i is Affected By Multiple SQL Vulnerabilities [CVE-2026-16908, CVE-2026-16967], at https://www.ibm.com/support/pages/node/7283294?myns=swgother&mynp=OCSWG60&mynp=OCSSTS2D&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSSTS2D-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10871
7.5 SJ10835
7.4 SJ10840
7.3 SJ10841
Security Bulletin: IBM i is Affected By A Privilege Escalation Vulnerability [CVE-2026-18669], at https://www.ibm.com/support/pages/node/7283278?myns=swgother&mynp=OCSWG60&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mynp=OCSSTS2D&mync=E&cm_sp=swgother-_-OCSWG60-OCSS9QQS-OCSSB23CE-OCSSKWKM-OCSSTS2D-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ11009
7.5 SJ10978
7.4 SJ10977
7.3 SJ10976
Security Bulletin: IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror [CVE-2026-16961], at https://www.ibm.com/support/pages/node/7283298?myns=swgother&mynp=OCSWG60&mynp=OCSS9QQS&mynp=OCSSB23CE&mynp=OCSSKWKM&mync=E&cm_sp=swgother-_-OCSWG60-OCSS9QQS-OCSSB23CE-OCSSKWKM-_-E. Affected Products and Versions:
IBM i Release 5770-SS1 PTF Number(s)
7.6 SJ10902
7.5 SJ10908
7.4 SJ10910
Security Bulletin: Multiple vulnerabilities in IBM Rational Developer for i (CVE-2026-10051, CVE-2026-6790, CVE-2026-8384, CVE-2026-10050, CVE-2026-59879, CVE-2026-59880), at https://www.ibm.com/support/pages/node/7283864?myns=swgother&mynp=OCSSAE4W&mync=E&cm_sp=swgother-_-OCSSAE4W-_-E. Affected Products and Versions: IBM Rational Developer for i 9.9.0.0 – 9.9.0.4
Security Bulletin: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities due to Apache CXF (CVE-2026-57819, CVE-2026-54225, CVE-2026-64958), at https://www.ibm.com/support/pages/node/7283567?myns=swgother&mynp=OCSSEQTP&mync=E&cm_sp=swgother-_-OCSSEQTP-_-E. Affected Product(s) and Version(s): IBM WebSphere Application Server – Liberty 17.0.0.3 – 26.0.0.8 and IBM WebSphere Application Server 9.0
Security Bulletin: IBM WebSphere Application Server Liberty is affected by a denial of service (CVE-2026-10571), at https://www.ibm.com/support/pages/node/7283485?myns=swgother&mynp=OCSSEQTP&mync=E&cm_sp=swgother-_-OCSSEQTP-_-E. Affected Product(s) and Version(s): IBM WebSphere Application Server – Liberty 17.0.0.3 – 26.0.0.8
Security Bulletin: IBM WebSphere Application Server Liberty is affected by a privilege escalation (CVE-2026-18499), at https://www.ibm.com/support/pages/node/7283489?myns=swgother&mynp=OCSSEQTP&mync=E&cm_sp=swgother-_-OCSSEQTP-_-E. Affected Product(s) and Version(s): WebSphere Application Server – Liberty 17.0.0.3 – 26.0.0.8
Security Bulletin: IBM WebSphere Application Server Liberty is affected by an authenication bypass (CVE-2026-14525), at https://www.ibm.com/support/pages/node/7283488?myns=swgother&mynp=OCSSEQTP&mync=E&cm_sp=swgother-_-OCSSEQTP-_-E. Affected Products and Versions: WebSphere Application Server – Liberty 17.0.0.3 – 26.0.0.8
And now for the firmware HIPER updates, and there is one for every machine as follows:
HIPER / IBM Power S1014 (9105-41B) / New Microcode for Firmware 1060 …. for 1060.81, at https://www.ibm.com/support/pages/node/7282963. No news yet.
HIPER / IBM Power S1022s (9105-22B) / New Microcode for Firmware 1060 …. for 1060.81 https://www.ibm.com/support/pages/node/7282963. No news yet.
HIPER / IBM Power S1022 (9105-22A) / New Microcode for Firmware 1060 …. for 1060.81, at https://www.ibm.com/support/pages/node/7282963. No news yet.
HIPER / IBM Power L1124 (9856-42H) / New Microcode for Firmware 1120 …. for 1120.01, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power L1122 (9856-22H) / New Microcode for Firmware 1120 …. for 1120.01, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power S1124 (9824-42A) / New Microcode for Firmware 1120 …. for 1120.01, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power S1122 (9824-22A) / New Microcode for Firmware 1120 …. for 1120.01, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power E1150 (9043-MRU) / New Microcode for Firmware 1120 …. for 1120.01, at, https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power E1180 (9080-HEU) / New Microcode for Firmware 1120 …. for 1120.01, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power L1124 (9856-42H) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power L1122 (9856-22H) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power S1124 (9824-42A) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power S1122 (9824-22A) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power E1150 (9043-MRU) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power E1180 (9080-HEU) / New Microcode for Firmware 1110 …. for 1110.31, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power System E980 Server (9080-M9S) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power System E950 Server (9040-MR9) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power System E980 Server (9080-M9S) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power System E950 Server (9040-MR9) / New Microcode for Firmware 950 ..950.H3, at https://www.ibm.com/support/pages/node/7283172?myns=pwrsmc&mynp=OCTI000B1&mync=E&cm_sp=pwrsmc-_-OCTI000B1-_-E. HMC Required.
HIPER / IBM Power System S924 Server (9009-42G) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7282963. No news yet.
HIPER / IBM Power System S914 Server (9009-41G) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7282963. No news yet.
HIPER / IBM Power System S922 Server (9009-22G) / New Microcode for Firmware 950 .. 950.H3, at https://www.ibm.com/support/pages/node/7282963. No news yet.
Here is the rundown of PTF Groups by IBM i release level since we last published:
PTF Groups 7.6:
- Security
- IBM HTTP Server for i
- IBM i Access Client Solutions V1.1.9.14
- QMGTOOLS
PTF Groups 7.5:
- Security
- IBM HTTP Server for i
- IBM i Access Client Solutions V1.1.9.14
- QMGTOOLS
- Defective PTFs
PTF Groups 7.4:
- Security
- IBM HTTP Server for i
- IBM i Access Client Solutions V1.1.9.14
- QMGTOOLS
PTF Groups 7.3:
- Security
- IBM HTTP Server for i
- IBM i Access Client Solutions V1.1.9.14
- QMGTOOLS
PTF Groups 7.2:
- None
One last thing: I have created a spreadsheet that organizes all of the new PTFs by operating system release to give you a finer-grained detail all in one place. You can link to it here.
Tip O’ The Week: IBM is gradually introducing SMS notifications for selected support updates. This feature is being rolled out across additional countries and update types over time. Go to this link to learn more.
New (or Updated) links added to the ‘Links’ tab in The Guide this week:
- HMC: Server Firmware Stand-alone IBM i Systems, 666875
New (or Updated) links added to the ‘QMGtools’ tab in The Guide this week:
- None
New (or Updated) links added to the ‘ACS_NAV’ tab in The Guide this week:
- None
New (or Updated) links added to the ‘Prtr Links’ tab in The Guide this week:
- None
New (or Updated) links Redbooks added this week:
- None
New (or Updated) stuff added to REF tab in The Guide this week:
- None
New (or Updated) links in the TAPE tab in The Guide this week:
- None
New (or Updated) links in the WAS tab in The Guide this week:
- None
The Guide at a glance: There were new defectives the week of 08/15/26. Defective PTF rundown – the latest defective for each release. Click on the Defective PTF link for your release in the Guide:
Defect Defective APAR Fixing
Date PTF PTF
-------- -------- --------- -----------------------
7.6 07/06/26 SJ10029 DT475474 xxxxxxxx (When available)(read the recommendations)
SJ09530 Read the cover letter-prerequisites!
See "What’s New" Entry above!!
7.5 08/13/26 SJ10844 DT498871 xxxxxxxx (When available)(read the recommendations)
Read the cover letter-prerequisites! See "What’s New" Entry above!!
7.4 04/10/26 SJ08675 DT467722 SJ09201 Same as above, Please read the cover letter
(When available)(read the recommendations)
Read the cover letter-prerequisites!
7.3 04/10/26 SJ08674 DT467722 SJ09200 (When available)(read the recommendations)
Be sure to access the link in The Guide for further details.
Below is the usual archive of the IBM i PTF Guide to help you work through the PTFs in chronological order:
August 15, 2026: Volume 28, Number 28
August 8, 2026: Volume 28, Number 27
August 1, 2026: Volume 28, Number 26
July 26, 2026: Volume 28, Number 25
July 18, 2026: Volume 28, Number 24
July 11, 2026: Volume 28, Number 23
July 4, 2026: Volume 28, Number 22
June 13, 2026: Volume 28, Number 21
June 6, 2026: Volume 28, Number 20
May 30, 2026: Volume 28, Number 19
May 23, 2026: Volume 28, Number 18
April 25, 2026: Volume 28, Number 17
April 18, 2026: Volume 28, Number 16
April 11, 2026: Volume 28, Number 15
April 4, 2026: Volume 28, Number 14
March 28, 2026: Volume 28, Number 13
March 23, 2026: Volume 28, Number 12
March 14, 2026: Volume 28, Number 11
March 7, 2026: Volume 28, Number 10
February 28, 2026: Volume 28, Number 09
February 21, 2026: Volume 28, Number 08
February 14, 2026: Volume 28, Number 07
February 7, 2026: Volume 28, Number 06
January 31, 2026: Volume 28, Number 05
January 24, 2026: Volume 28, Number 04
January 17, 2026: Volume 28, Number 03
January 10, 2026: Volume 28, Number 02
January 3, 2026: Volume 28, Number 01
December 27, 2025: Volume 27, Number 52
December 20, 2025: Volume 27, Number 51
December 13, 2025: Volume 27, Number 50
November 29, 2025: Volume 27, Number 48
November 22, 2025: Volume 27, Number 47
November 15, 2025: Volume 27, Number 46
November 8, 2025: Volume 27, Number 45
November 1, 2025: Volume 27, Number 44
October 25, 2025: Volume 27, Number 43
October 18, 2025: Volume 27, Number 42
October 11, 2025: Volume 27, Number 41
October 4, 2025: Volume 27, Number 40
September 27, 2025: Volume 27, Number 39
September 20, 2025: Volume 27, Number 38
September 13, 2025: Volume 27, Number 37
September 6, 2025: Volume 27, Number 36
August 30, 2025: Volume 27, Number 35
August 23, 2025: Volume 27, Number 34
August 16, 2025: Volume 27, Number 33
August 9, 2025: Volume 27, Number 32
August 2, 2025: Volume 27, Number 31
July 26, 2025: Volume 27, Number 30
July 19, 2025: Volume 27, Number 29
July 12, 2025: Volume 27, Number 28
July 5, 2025: Volume 27, Number 27
June 28, 2025: Volume 27, Number 26
June 21, 2025: Volume 27, Number 25
June 14, 2025: Volume 27, Number 24
June 7, 2025: Volume 27, Number 23
May 31, 2025: Volume 27, Number 22
May 24, 2025: Volume 27, Number 21
May 17, 2025: Volume 27, Number 20
May 10, 2025: Volume 27, Number 19
May 3, 2025: Volume 27, Number 18
April 26, 2025: Volume 27, Number 17
April 21, 2025: Volume 27, Number 16
April 12, 2025: Volume 27, Number 15
April 5, 2025: Volume 27, Number 14
March 29, 2025: Volume 27, Number 13
March 22, 2025: Volume 27, Number 12
March 15, 2025: Volume 27, Number 11
March 8, 2025: Volume 27, Number 10
March 1, 2025: Volume 27, Number 09
February 22, 2025: Volume 27, Number 08
February 15, 2025: Volume 27, Number 07
February 8, 2025: Volume 27, Number 06
February 1, 2025: Volume 27, Number 05
January 25, 2025: Volume 27, Number 04
January 18, 2025: Volume 27, Number 03
January 11, 2025: Volume 27, Number 02
January 04, 2025: Volume 27, Number 01
December 21, 2024: Volume 26, Number 50
December 14, 2024: Volume 26, Number 49
December 7, 2024: Volume 26, Number 48
November 30, 2024: Volume 26, Number 47
November 23, 2024: Volume 26, Number 46
November 16, 2024: Volume 26, Number 45
November 9, 2024: Volume 26, Number 44
November 2, 2024: Volume 26, Number 43
October 26, 2024: Volume 26, Number 42
October 19, 2024: Volume 26, Number 41
October 12, 2024: Volume 26, Number 40
October 9, 2024: Volume 26, Number 39
September 28, 2024: Volume 26, Number 38
September 21, 2024: Volume 26, Number 37
September 14, 2024: Volume 26, Number 36
September 7, 2024: Volume 26, Number 35
August 31, 2024: Volume 26, Number 34
August 24, 2024: Volume 26, Number 33
August 17, 2024: Volume 26, Number 32
August 11, 2024: Volume 26, Number 31
August 3, 2024: Volume 26, Number 30
July 27, 2024: Volume 26, Number 29
July 20, 2024: Volume 26, Number 28

