Network Boot Vulnerability in IBM PowerVM Hypervisor Firmware
CVE-2026-17414

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17414?

The IBM PowerVM Hypervisor is susceptible to a security flaw during the network boot process. An unauthenticated attacker within the same network can disrupt a partition’s boot sequence. If operating system secure boot is not enabled, the attacker can also replace the boot image, posing significant risks to the confidentiality, integrity, and availability of system resources. This vulnerability impacts only the partitions engaged in a network boot, leaving others unaffected.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.