CVE-2026-16815 presents as a stack-based buffer overflow on IBM i with denial-of-service as confirmed impact and information disclosure marked as potential. The four-version span—7.3 through 7.6—should concern you more than the CVSS score. This breadth indicates the vulnerable code path survived at least two major release cycles, suggesting either a newly-introduced flaw in compatibility machinery or a dormant defect in preserved layers that operators rarely invoke directly.
The 'potentially obtain sensitive information' phrasing is not uncertainty—it follows a documented IBM disclosure pattern. Historical IBM i CVEs consistently show this qualifier resolves toward confirmed disclosure once a proof-of-concept emerges, typically months to years after initial publication. Treat the qualifier as a signal that the exploitation ceiling hasn't been publicly demonstrated yet, not that it may not exist.
What should drive your prioritization is the exposure geometry. IBM i systems cluster in banking, healthcare, manufacturing, and critical infrastructure—environments where adversaries already have positioning through supply chain access or managed service relationships. For these targets, the 'remote attacker' framing in the CVE is largely irrelevant. The question is whether actors with existing IBM i access can escalate from DoS to disclosure, and the historical pattern says they often can.
The version distribution creates asymmetric exposure. Organizations running 7.3 in production have by definition prioritized stability over currency—they are the least likely to patch quickly and the most likely to remain exposed. The 7.3 end of the spectrum concentrates your blast radius concern, and that's where visibility is poorest.
One critical gap remains: the triggering surface. Whether this requires authenticated access (TN5250 session) or is reachable without credentials fundamentally changes your risk model. Treat this as potentially internet-facing until IBM confirms the access requirement. If you cannot determine the surface, assume unauthenticated network reachability and prioritize patching accordingly.