Out-of-Bounds Read Vulnerability in IBM PowerVM Hypervisor
CVE-2026-18870

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 September 2026

What is CVE-2026-18870?

The IBM PowerVM Hypervisor has a vulnerability that enables a remote attacker to exploit an out-of-bounds read condition. This flaw can potentially allow unauthorized access to sensitive information, leading to security breaches and data exposure. Various versions of the firmware, including FW1120.00 to FW1120.01, FW1110.00 to FW1110.31, FW1060.00 to FW1060.81, and FW950.00 to FW950.H3, are affected. Organizations utilizing these systems should be alert to the implications of this vulnerability and consider necessary updates and security measures.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.