CVE-2026-15961
Received Received - Intake

IBM PowerVM Hypervisor Format String Vulnerability

Vulnerability report for CVE-2026-15961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1110.00 (inc) to FW1110.30 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.80 (inc)
ibm powervm_hypervisor FW1120.00
ibm powervm_hypervisor FW1110.00
ibm powervm_hypervisor FW1060.00

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-134 The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15961 is a format string vulnerability in IBM PowerVM Hypervisor firmware. A local attacker could exploit improper format string handling to read sensitive information or crash the system, leading to a denial of service. The flaw exists in specific firmware versions of PowerVM Hypervisor.

Detection Guidance

Detecting this vulnerability requires checking the firmware version of IBM PowerVM Hypervisor. Compare your system's firmware against affected versions: FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80. Use IBM's tools or commands like 'lsmcode' on AIX or 'systemctl' on Linux to list firmware versions.

Impact Analysis

If you use IBM Power Systems with affected PowerVM Hypervisor firmware versions, an attacker with local access could steal data or disrupt operations. This may lead to unauthorized information disclosure or system unavailability. The impact depends on attacker privileges and system configuration.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations if sensitive data is exposed due to the flaw. Proper mitigation via firmware updates is necessary to maintain compliance.

Mitigation Strategies

Install the latest firmware updates provided by IBM, such as FW1110.31, FW1120.01, or FW1060.81, depending on your current version. Ensure no workarounds are applied and subscribe to IBM security bulletins for future updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart