Arbitrary Code Execution Vulnerability in IBM PowerVM Hypervisor
CVE-2026-16661
8.2HIGH
What is CVE-2026-16661?
IBM PowerVM Hypervisor has a vulnerability within the service processor mailbox interface that could allow an attacker with authenticated service-level access to exploit the system. This exploitation might enable execution of arbitrary code in the host firmware runtime, granting the attacker full control over the managed systems. Such access poses risks to confidentiality, integrity, and availability, making it essential for users to address the threat by securing their systems and applying pertinent patches.
Affected Version(s)
PowerVM Hypervisor FW1120.00
PowerVM Hypervisor FW1110.00
PowerVM Hypervisor FW1060.00