IBM i PTF Guide, Volume 28, Number 27
August 10, 2026 Doug Bidwell
Welcome to this week. You have some issues with IBM i Access Client Services to deal with as well as a new security bulletin.
Let’s start with the ACS updates, which are rolled up into ACS 1.1.9.14 and which you can read more about at this link. All prior versions are vulnerable to:
- Arbitrary code execution on Windows when installed for all users due to publicly writeable directory and configuration file.
- Injection of rogue certificate authority due to publicly writeable truststore.
- Zip slip path traversal exploit when importing a configuration.
- Versions 1.1.8.3 through 1.1.9.13 are vulnerable to downloading unverified
