Power Systems Firmware IBM Power Systems Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Power Systems Firmware.

By the Year

In 2026 there have been 28 vulnerabilities in IBM Power Systems Firmware with an average score of 7.5 out of ten.

Year Vulnerabilities Average Score
2026 28 7.49

It may take a day or so for new Power Systems Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Power Systems Firmware Security Vulnerabilities

IBM PowerVM PKS & vTPM AES key strength issue (FW1060-1110)
CVE-2026-4936 5.1 - Medium - August 19, 2026

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

Insufficient Entropy

IBM PowerVM Hypervisor FW1110.00-1110.20 Local Admin Decrypt via Low Entropy
CVE-2026-4937 5.3 - Medium - August 19, 2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

Insufficient Entropy

IBM PowerVM Hypervisor Authenticated Service Mailbox RCE CVE202616707
CVE-2026-16707 8.2 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

Out-of-bounds Read

IBM PowerVM Hypervisor FW1120+ iSCSI SAN Network Boot DoS
CVE-2026-17028 6.5 - Medium - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.

Out-of-bounds Read

IBM PowerVM Hypervisor Call Interface Data Injection Causing Crash (FW 1120)
CVE-2026-17091 8.4 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

Integer Overflow or Wraparound

IBM PowerVM Hypervisor <=1120: Hypercall VCPU Hang Vulnerability
CVE-2026-17097 7.3 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

out-of-bounds array index

IBM PowerVM Hypervisor (FW1120: Network Boot RCE)
CVE-2026-18821 7.5 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

Memory Corruption

IBM VMI Crash via Auth Admin (FW1110-1110.30, FW1120.00, FW1060-1060.80)
CVE-2026-16724 4.5 - Medium - August 19, 2026

IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through FW1060.80 is affected by a vulnerability in the Virtualization Management Interface (VMI). An attacker with authenticated administrator-level access can cause the VMI to crash. The VMI will restart automatically; however, repeated exploitation could result in a sustained availability impact.

Integer Overflow or Wraparound

IBM PowerVM Hypervisor Crash via Config Parsing (FW1060-FW1120)
CVE-2026-18871 7.3 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, resulting in an integrity and availability impact to the managed system.

Stack Overflow

IBM PowerVM Hypervisor FW pre1120 Network Boot Partition Firmware RCE
CVE-2026-17414 8.1 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

Improper Input Validation

IBM PowerVM Hypervisor FW1110.00-1110.30 Service Processor Mailbox RCE
CVE-2026-16661 8.2 - High - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system.

Integer Overflow or Wraparound

IBM Power Systems Firmware BMC/FSP memory attack (FW1120.00-1060.80)
CVE-2026-16933 8.2 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Integer Overflow or Wraparound

IBM Power Systems Firmware NVRAM parsing flaw (FW950, OP940) Crash & Memory Corrupt
CVE-2026-17042 7.3 - High - August 19, 2026

IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention clearing NVRAM via the service processor to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.

Out-of-bounds Read

IBM Power Sys FW1050-1110: BMC/FSP Interface Privileged Exploit
CVE-2026-17063 7.9 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.

AuthZ

IBM Power Systems Firmware ASMI RCE before FW1120.00
CVE-2026-16687 9.6 - Critical - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

Stack Overflow

IBM Power Systems Firmware FSP Auth Bypass (FW1120)
CVE-2026-16835 9.6 - Critical - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.

Improper Certificate Validation

IBM Power Sys Firmware <=FW1120: FSP Net Prot Auth Code Exec
CVE-2026-16832 8.4 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

Stack Overflow

IBM Power Sys Firmware FW1120.00-1110.30 FSP Access RCE -> Availability
CVE-2026-16938 6.9 - Medium - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention clearing the affected configuration to restore normal operation. Successful exploitation results in an availability impact to the managed system.

AuthZ

IBM Power Systems Firmware ASMI Web UI Remote Priv Esc CVE-2026-18848
CVE-2026-18848 8.3 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system.

Session Riding

IBM Power Systems Firmware ASMI Web Interface Crash (FW950-1120)
CVE-2026-16828 7.6 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can cause the ASMI web server to crash with possible memory corruption and generate an error log; hosted partitions are not affected. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.

Out-of-bounds Read

IBM Power Sys Firmware FW1110-1120 Arbitrary Code Exec via BMC Host Interface
CVE-2026-17494 8.2 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Stack Overflow

IBM Power Systems Firmware BMC/FSP Full Control (FW10601120)
CVE-2026-17429 8.1 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can write arbitrary data to hardware control registers, allowing full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

AuthZ

IBM Power BMC/FSP RCE via firmware before FW1120.00
CVE-2026-16930 8.2 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can execute arbitrary code on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

AuthZ

IBM Power Systems FSP Firmware Authenticated Code Exec (FW1120.00FW950.H2)
CVE-2026-18681 6.8 - Medium - August 19, 2026

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Stack Overflow

IBM Power Systems Firmware pre-FW1120.00 Host Firmware Parsing RCE
CVE-2026-17093 8.2 - High - August 19, 2026

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.

Stack Overflow

IBM Power Systems Firmware <1120/1110/1060: Reg Leak via Service Proc
CVE-2026-19321 6.7 - Medium - August 19, 2026

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.

Integer Overflow or Wraparound

IBM Power Firmware Image Validation Vulnerability (Arbitrary Code Exec)
CVE-2026-19234 8.2 - High - August 19, 2026

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.

Stack Overflow

IBM PowerVM Hypervisor Format String Flaw (FW1060-1120) Vulnerability
CVE-2026-15961 5.2 - Medium - August 19, 2026

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.

Use of Externally-Controlled Format String

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Power Systems Firmware or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe