Arbitrary Code Execution Vulnerability in IBM Power Systems Firmware
CVE-2026-16930
8.2HIGH
What is CVE-2026-16930?
IBM Power Systems Firmware versions FW1120.00, FW1110.00 to FW1110.30, and FW1060.00 to FW1060.80 are prone to a significant vulnerability that affects the interface between the Baseboard Management Controller (BMC) or the Firmware Service Processor (FSP) and the host system. An attacker with either service account or root access to the BMC/FSP can leverage this flaw to execute arbitrary code on the host system, leading to complete control over the system and all connected partitions. This extensive access can severely undermine the confidentiality, integrity, and availability of the affected systems.
Affected Version(s)
Power Systems Firmware FW1120.00
Power Systems Firmware FW1110.00
Power Systems Firmware FW1060.00