IBM PowerVM PKS & vTPM AES key strength issue (FW1060-1110)
CVE-2026-4936 Published on August 19, 2026
Power System Insufficient Entropy
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.
Vulnerability Analysis
Weakness Type
Insufficient Entropy
The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Products Associated with CVE-2026-4936
Want to know whenever a new CVE is published for IBM Power Systems Firmware? stack.watch will email you.
Affected Versions
IBM PowerVM Hypervisor:- Version FW1110.00, <= FW1110.20 is affected.
- Version FW1060.00, <= FW1060.71 is affected.
- Version FW950.00, <= FW950.H2 is affected.