HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-16907 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec...

·Source: NIST NVD

Updated:

Executive Summary

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

Analysis

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking. CVSS Score: 7.6. Published: 2026-08-12T18:17:24.890.

Indicators of Compromise (1)

CVE (1)
CVE-2026-16907
Source Attribution

Originally published by NIST NVD on Aug 12, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification...

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

CVE-2026-18316
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

CVE-2026-18432
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-16098 — The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U...

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delet

CVE-2026-16098
NIST NVD