Vulnerability in IBM Power Systems Firmware Affects Multiple Versions
CVE-2026-16832

8.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-16832?

A vulnerability exists in the IBM Power Systems Firmware affecting multiple versions, specifically through the FSP management network protocol. This issue allows an attacker with authenticated HMC administrator access to execute arbitrary code on the hardware service processor. This exploitation can grant an attacker complete control over the managed system, potentially leading to severe impacts on confidentiality, integrity, and availability of system resources. Users are encouraged to apply security patches as advised by IBM.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.