IBM AIX users urged to patch immediately as researchers sound alarm on critical flaws

IBM AIX users urged to patch immediately as researchers sound alarm on critical flaws

By Emma Woollacott
Publication Date: 2025-11-18 11:04:00

IBM has issued patches for four major flaws in IBM AIX and VIOS that allow a remote, unprivileged attacker to achieve arbitrary command execution on an exposed IBM Network Installation Manager (NIM).

The four vulnerabilities, tracked as CVE‑2025‑36250, CVE‑2025‑36251, CVE‑2025‑36236, and CVE‑2025‑36096, affect IBM AIX 7.2 and 7.3 as well as IBM VIOS 3.1 and 4.1 environments, with three of the four receiving a critical CVSS score.