IBM i NetServer, Improper Authentication (NTLM Session Negotiation), CVE-2026-16867 (CRITICAL) -DC-Aug2026-1557

Listen to this Post

CVE-2026-16867 is a critical vulnerability affecting IBM i operating system versions 7.3, 7.4, 7.5, and 7.6. The flaw resides in the NetServer component’s handling of NTLM (NT LAN Manager) authentication sessions. During NTLM session negotiation, the system improperly validates the authentication credentials of connecting clients. This allows a remote, unauthenticated attacker to bypass the normal authentication process and assume the identity of a legitimate user. The root cause is a weakness in the authentication logic (CWE-287: Improper Authentication), where the server fails to sufficiently prove that an actor’s claimed identity is correct. By exploiting this flaw, an attacker can gain unauthorized access to server resources with the same privileges as the impersonated user. The vulnerability is remotely exploitable over a network without any user interaction. NIST’s CVSS v3.1 base score is 9.8 (CRITICAL), while IBM Corporation’s own assessment rates it as 8.1 (HIGH). The flaw is part of a larger set of vulnerabilities affecting IBM i NetServer. The NVD published the CVE on August 13, 2026, with the last modification on August 17, 2026. IBM has released a security advisory (ID: 7283573) and strongly recommends immediate remediation.

DailyCVE Form:

Platform: IBM i 7.3-7.6
Version: 7.3,7.4,7.5,7.6
Vulnerability: Improper NTLM Authentication
Severity: CRITICAL (9.8 CVSS)
date: 2026-08-13

Prediction: 2026-08-20 (IBM patch)

What Undercode Say:

Analytics show active scanning for IBM i NetServer NTLM vulnerabilities since mid-August 2026. EPSS score is 0.40% with ~33% percentile. Public proof-of-concept exploits are being monitored on GitHub.

Check IBM i version
DSPSFWRSC
Check NTLM authentication settings
WRKREGINF
Query authentication logs for anomalies
DSPAUTLOG
Monitor for unauthorized NTLM sessions
WRKACTJOB SBS(QSERVER)

Exploit: (Educational Purposes!)

An attacker crafts a malicious NTLM authentication request to the NetServer service (port 139/tcp, 445/tcp). By manipulating the NTLM session negotiation parameters, the attacker can force the server to accept a spoofed identity without valid credentials. This grants the attacker the privileges of a targeted authenticated user, allowing access to files, directories, and other server resources. The attack requires network access to the IBM i system but no prior authentication or user interaction. Successful exploitation can lead to complete compromise of the system’s confidentiality, integrity, and availability.

Protection:

Immediately apply IBM security advisory fixes (ID: 7283573). Upgrade IBM i to the latest supported security level. Review and harden NTLM authentication configurations. Monitor authentication logs for suspicious activity. Restrict network access to NetServer services (ports 139, 445) using firewalls.

Impact:

Remote unauthenticated attackers can access server resources with privileges of an authenticated user. Full compromise of confidentiality, integrity, and availability (CIA triad). Potential for data theft, system manipulation, and denial of service. Affects all supported IBM i versions 7.3 through 7.6.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top