IBM published patches today for 18 CVEs in IBM i 7.3, 7.4, 7.5, and 7.6, covering a wide spread of flaws in the operating system’s core components.
The issues include authenticated remote code execution, privilege escalation, injection, buffer overflow, path traversal, and time-of-check time-of-use race conditions. In plain terms, different parts of the same OS were accepting bad input or handling privileges unsafely, so a partial fix can still leave other attack paths open on the host.
For shops that run IBM i as a shared enterprise platform, the exposure is systemic rather than tied to one service. If the system sits under multiple internal applications or trust relationships, the remaining unpatched subsystems can still carry risk even after one piece is updated.