Security Advisory
IBM i and Java: multiple IBM Java SDK and Runtime vulnerabilities
What Happened
IBM published a security bulletin covering six CVEs (CVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007) affecting the IBM Java SDK and IBM Java Runtime as shipped on IBM i.
Why It Matters
IBM Java underpins a wide range of IBM i middleware and third-party applications. Because Java versions are frequently pinned to specific application requirements, these fixes are easy to miss if version tracking is not centralized.
Recommended Actions
- Inventory every installed Java version across LPARs, including versions pinned for specific applications
- Apply IBM's release-specific PTFs per the bulletin's affected-product table
- Coordinate with application owners before upgrading shared Java runtimes to avoid compatibility breaks