Arbitrary Code Execution Vulnerability in IBM PowerVM Hypervisor
CVE-2026-16661

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-16661?

IBM PowerVM Hypervisor has a vulnerability within the service processor mailbox interface that could allow an attacker with authenticated service-level access to exploit the system. This exploitation might enable execution of arbitrary code in the host firmware runtime, granting the attacker full control over the managed systems. Such access poses risks to confidentiality, integrity, and availability, making it essential for users to address the threat by securing their systems and applying pertinent patches.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.