<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IBM I (7.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ibm-i-7.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 18:48:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ibm-i-7.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Uncontrolled Search Path Vulnerability in IBM i</title><link>https://feed.craftedsignal.io/briefs/2026-08-12-cve-2026-16860-ibm-i/</link><pubDate>Wed, 12 Aug 2026 18:48:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-12-cve-2026-16860-ibm-i/</guid><description>IBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows a remote authenticated attacker to execute arbitrary code with elevated privileges.</description><content:encoded><![CDATA[<p>IBM i versions 7.3, 7.4, 7.5, and 7.6 are vulnerable to an uncontrolled search path element vulnerability (CVE-2026-16860). This flaw allows a remote authenticated attacker to influence the search path used by the system to locate binaries or libraries. By manipulating this path, an attacker can trick the system into executing arbitrary code rather than the intended legitimate executable. This vulnerability is rated with a CVSS 3.1 base score of 9.9, reflecting its critical impact on system integrity and confidentiality. Because successful exploitation requires authentication, it represents a significant lateral movement or privilege escalation risk for organizations relying on IBM i in their infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-16860 enables an authenticated attacker to execute arbitrary code with elevated privileges on the affected IBM i systems. This could lead to a total compromise of the affected environment, allowing for unauthorized data access, system modification, or persistent access by malicious actors. Organizations running IBM i in critical business or financial operations are at highest risk if they have compromised user accounts or internal malicious insiders.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of IBM i versions 7.3, 7.4, 7.5, and 7.6 within the enterprise environment.</li>
<li>Review vendor-provided security patches for CVE-2026-16860 and apply them to all affected IBM i systems immediately.</li>
<li>Audit user permissions and access logs to identify any anomalous execution patterns or suspicious modification of system paths by authenticated users.</li>
<li>Implement stringent monitoring for processes spawned from non-standard library or binary paths on the affected IBM i environment.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>ibm-i</category><category>privilege-escalation</category><category>cve-2026-16856</category></item></channel></rss>