IBM i PTF Guide, Volume 28, Number 32
September 21, 2026 Doug Bidwell
Another week, and another bunch of security vulnerabilities for the IBM i platform. Plus a slew of stuff to update IBM i 7.3 through IBM i 7.6. Let us start with the security issues and patches, as we always do, and count them off to 11 so we can keep track of them.
1. Security Bulletin: IBM Db2 Mirror for i is vulnerable to Authentication Bypass by Spoofing [CVE-2026-18065], which you can read HERE. Affected Products and Versions:
IBM i Release 5770-DBM PTF Numbers 7.6 SJ11475 7.5 SJ11474 7.4 SJ11471
2. Security Bulletin: IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime, which you can read HERE. A total of 15 CVEs are affected, check the link for details! Affected Products and Versions:
IBM i Release 5770=JV1 PTF Numbers 7.6 SJ10999 SJ10983 SJ11003 SJ10987 SJ11143 SJ11146 SJ10933 SJ10944 7.5 SJ10998 SJ10982 SJ11002 SJ10986 SJ10995 SJ11004 SJ11142 SJ11145 SJ10932 SJ10946 7.4 SJ10997 SJ10981 SJ11001 SJ10985 SJ10994 SJ11184 SJ11141 SJ11144 7.3 SJ10996 SJ10980 SJ11000 SJ10984 SJ10993 SJ11011
3. Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i, which you can read HERE. A total of 5 CVEs affected, check the link for details! Affected Products and Versions:
IBM i Release 5770=SS1, Opt 3 PTF Numbers 7.6 SJ11196 SJ11337 7.5 SJ11197 SJ11336 7.4 SJ11200 SJ11335 7.3 SJ11187 SJ11394
Also Affected Products and Versions:
IBM i Release 5770=SS1, Opt 34 PTF Numbers 7.6 SJ11377 7.5 SJ11376 7.4 SJ11375 7.3 SJ11374
4. Security Bulletin: IBM Db2 Mirror for i is vulnerable to Cross-Site Request Forgery [CVE-2026-17047], which you can read HERE. Affected Products and Versions:
IBM i Release 5770=SS1 PTF Numbers 7.6 SJ11337 7.5 SJ11336 7.4 SJ11335
5. Security Bulletin: IBM WebSphere Application Server is affected by a privilege escalation (CVE-2026-11545), which you can read HERE. For IBM WebSphere Application Server traditional, for V9.0.0.0 through 9.0.5.28, apply Fix Pack 9.0.5.29 (availability September 2026) or later fix pack. For V8.5.0.0 through 8.5.5.30, apply Fix Pack 8.5.5.31 (availability September 2026) or later fix pack.
6. Security Bulletin: IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability (CVE-2026-11710), which you can read HERE. For IBM WebSphere Application Server traditional, for V8.5.0.0 through 8.5.5.30, apply Fix Pack 8.5.5.31 (availability September 2026) or later fix pack.
7. Security Bulletin: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities, which you can read HERE. A total of 25 CVE;s affected, check the link for details! For IBM WebSphere Application Server traditional, for V9.0.0.0 through 9.0.5.28, apply Fix Pack 9.0.5.29 (availability September 2026) or later fix pack. For V8.5.0.0 through 8.5.5.30, apply Fix Pack 8.5.5.31 (availability September 2026) or later fix pack.
8. Security Bulletin: IBM WebSphere Application Server Liberty is affected by an improper restriction of XML External Entity Reference vulnerability due to Apache CXF (CVE-2026-49875), which you can read HERE. Affected Products and Versions:
Affected Product(s) Version(s) WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.9 (See link for further details)
9. Security Bulletin: IBM WebSphere Application Server Liberty is affected by uncontrolled resource consumption vulnerabilities due to Apache Neethi (CVE-2026-66142, CVE-2026-66143, CVE-2026-66144), which you can read HERE. A total of 3 CVE;s affected, check the link for details! Affected Products and Versions:
Affected Product(s) Version(s) WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.9
10. Security Bulletin: IBM WebSphere Application Server Liberty is affected by an XML External Entity Injection vulnerability due to Apache CXF (CVE-2026-65432), which you can read HERE. Affected Products and Versions:
Affected Product(s) Version(s) WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.9
11. Security Bulletin: A Vulnerability in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU plus deferred CVE-2026-16440, which you can read HERE. Affected Products and Versions:
Affected Product(s) Version(s) WebSphere Application Server 8.5 WebSphere Application Server 9.0 IBM WebSphere Application Server - Liberty Continuous delivery
Finally, inhale and exhale a few times, here is the rundown of PTF Groups by IBM i release level since we last published:
PTF Groups 7.6:
- Java
- IBM HTTP Server for i
- IBM MQ for IBM i – v9.3.0/v9.4.0
- Fix list for IBM WebSphere Application Server Liberty
- Defective PTFs
- Visual Studio Code for IBM i
PTF Groups 7.5:
- Java
- IBM HTTP Server for i
- IBM MQ for IBM i – v9.2.0/v9.3.0/v9.4.0
- Fix list for IBM WebSphere Application Server Liberty
- Visual Studio Code for IBM i
PTF Groups 7.4:
- Java
- IBM HTTP Server for i
- MQ for IBM i – v9.0.0/v9.1.0/v9.2.0/v9.3.0
- Fix list for IBM WebSphere Application Server Liberty
- Visual Studio Code for IBM i
PTF Groups 7.3:
- Java
- IBM HTTP Server for i
- MQ for IBM i – v7.1.0/v8.0.0/V9.0.0/V9.1/V9.265
- Fix list for IBM WebSphere Application Server Liberty
- Visual Studio Code for IBM i
PTF Groups 7.2:
- None
Tip O’ The Week: (this may or may not resolve your problem, for some, it worked!!)
Unable to obtain CONSOLE or VIRTUAL Control Panel after Updating to ACS version 1.1.9.15
- Close all the ACS windows and
- Go to: C:\Users\Administrator\Documents\IBM\iAccessClient\Private\ and then delete the folder.Administrator and then
- Restart ACS.
Submitted by our friends at TRACnet. . . .
New (or Updated) links added to the ‘Links’ tab in The Guide this week:
- Proxy: IBM i Web Applications – Configuring for Proxy Environments, 7286735
New (or Updated) links added to the ‘QMGtools’ tab in The Guide this week:
- None
New (or Updated) links added to the ‘ACS_NAV’ tab in The Guide this week:
- None
New (or Updated) links added to the ‘Prtr Links’ tab in The Guide this week:
- None
New (or Updated) links Redbooks added this week:
- None
New (or Updated) stuff added to REF tab in The Guide this week:
- None
New (or Updated) links in the TAPE tab in The Guide this week:
- None
New (or Updated) links in the WAS tab in The Guide this week:
- None
The Guide at a glance: There were new defectives the week of 09/12/26. Defective PTF rundown – the latest defective for each release. Click on the Defective PTF link for your release in the Guide:
Defect Defective APAR Fixing Date PTF PTF -------- -------- --------- ----------------------- 7.6 09/10/26 MJ10605 DT499686 MJ11309 (When available)(read the recommendations) MJ10457 Read the cover letter-prerequisites! MJ07695 7.5 08/27/26 SJ10844 DT498782 SJ11182 (When available)(read the recommendations) SJ10692 Read the cover letter-prerequisites! SJ09231 SJ08956 SJ08706 SJ08575 SJ08425 7.4 08/27/26 SJ08675 DT498782 SJ11183 Same as above, Please read the Cover letter SJ10873 (When available)(read the recommendations) SJ09230 Read the cover letter-prerequisites! SJ08957 SJ08705 SJ08576 SJ08424 7.3 04/10/26 SJ08674 DT467722 SJ09200 (When available)(read the recommendations)
Be sure to access the link in The Guide for further details.
Below is the usual archive of the IBM i PTF Guide to help you work through the PTFs in chronological order:
September 12, 2026: Volume 28, Number 32
September 4, 2026: Volume 28, Number 31
August 29, 2026: Volume 28, Number 30
August 22, 2026: Volume 28, Number 29
August 15, 2026: Volume 28, Number 28
August 8, 2026: Volume 28, Number 27
August 1, 2026: Volume 28, Number 26
July 26, 2026: Volume 28, Number 25
July 18, 2026: Volume 28, Number 24
July 11, 2026: Volume 28, Number 23
July 4, 2026: Volume 28, Number 22
June 13, 2026: Volume 28, Number 21
June 6, 2026: Volume 28, Number 20
May 30, 2026: Volume 28, Number 19
May 23, 2026: Volume 28, Number 18
April 25, 2026: Volume 28, Number 17
April 18, 2026: Volume 28, Number 16
April 11, 2026: Volume 28, Number 15
April 4, 2026: Volume 28, Number 14
March 28, 2026: Volume 28, Number 13
March 23, 2026: Volume 28, Number 12
March 14, 2026: Volume 28, Number 11
March 7, 2026: Volume 28, Number 10
February 28, 2026: Volume 28, Number 09
February 21, 2026: Volume 28, Number 08
February 14, 2026: Volume 28, Number 07
February 7, 2026: Volume 28, Number 06
January 31, 2026: Volume 28, Number 05
January 24, 2026: Volume 28, Number 04
January 17, 2026: Volume 28, Number 03
January 10, 2026: Volume 28, Number 02
January 3, 2026: Volume 28, Number 01
December 27, 2025: Volume 27, Number 52
December 20, 2025: Volume 27, Number 51
December 13, 2025: Volume 27, Number 50
November 29, 2025: Volume 27, Number 48
November 22, 2025: Volume 27, Number 47
November 15, 2025: Volume 27, Number 46
November 8, 2025: Volume 27, Number 45
November 1, 2025: Volume 27, Number 44
October 25, 2025: Volume 27, Number 43
October 18, 2025: Volume 27, Number 42
October 11, 2025: Volume 27, Number 41
October 4, 2025: Volume 27, Number 40
September 27, 2025: Volume 27, Number 39
September 20, 2025: Volume 27, Number 38
September 13, 2025: Volume 27, Number 37
September 6, 2025: Volume 27, Number 36
August 30, 2025: Volume 27, Number 35
August 23, 2025: Volume 27, Number 34
August 16, 2025: Volume 27, Number 33
August 9, 2025: Volume 27, Number 32
August 2, 2025: Volume 27, Number 31
July 26, 2025: Volume 27, Number 30
July 19, 2025: Volume 27, Number 29
July 12, 2025: Volume 27, Number 28
July 5, 2025: Volume 27, Number 27
June 28, 2025: Volume 27, Number 26
June 21, 2025: Volume 27, Number 25
June 14, 2025: Volume 27, Number 24
June 7, 2025: Volume 27, Number 23
May 31, 2025: Volume 27, Number 22
May 24, 2025: Volume 27, Number 21
May 17, 2025: Volume 27, Number 20
May 10, 2025: Volume 27, Number 19
May 3, 2025: Volume 27, Number 18
April 26, 2025: Volume 27, Number 17
April 21, 2025: Volume 27, Number 16
April 12, 2025: Volume 27, Number 15
April 5, 2025: Volume 27, Number 14
March 29, 2025: Volume 27, Number 13
March 22, 2025: Volume 27, Number 12
March 15, 2025: Volume 27, Number 11
March 8, 2025: Volume 27, Number 10
March 1, 2025: Volume 27, Number 09
February 22, 2025: Volume 27, Number 08
February 15, 2025: Volume 27, Number 07
February 8, 2025: Volume 27, Number 06
February 1, 2025: Volume 27, Number 05
January 25, 2025: Volume 27, Number 04
January 18, 2025: Volume 27, Number 03
January 11, 2025: Volume 27, Number 02
January 04, 2025: Volume 27, Number 01
December 21, 2024: Volume 26, Number 50
December 14, 2024: Volume 26, Number 49
December 7, 2024: Volume 26, Number 48
November 30, 2024: Volume 26, Number 47
November 23, 2024: Volume 26, Number 46
November 16, 2024: Volume 26, Number 45
November 9, 2024: Volume 26, Number 44
November 2, 2024: Volume 26, Number 43
October 26, 2024: Volume 26, Number 42
October 19, 2024: Volume 26, Number 41
October 12, 2024: Volume 26, Number 40
October 9, 2024: Volume 26, Number 39
September 28, 2024: Volume 26, Number 38
September 21, 2024: Volume 26, Number 37

