Firmware Vulnerability in IBM PowerVM Hypervisor Products
CVE-2026-17504

5.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 September 2026

What is CVE-2026-17504?

The IBM PowerVM Hypervisor is susceptible to a firmware vulnerability that arises during the partition firmware runtime. Attackers with root access may exploit this flaw by sending a specially crafted request to the partition firmware, potentially leading to a system crash and memory corruption. It is critical for users running affected firmware versions to apply relevant patches and enhance their cybersecurity measures to mitigate risks associated with this vulnerability.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.