CVE-2026-16661
Received Received - Intake

IBM PowerVM Hypervisor Firmware Code Execution Vulnerability

Vulnerability report for CVE-2026-16661, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1110.00 (inc) to FW950.H2 (inc)
ibm powervm_hypervisor fw1120.00
ibm powervm_hypervisor to fw1110.30 (inc)
ibm powervm_hypervisor to fw1060.80 (inc)
ibm powervm_hypervisor to fw950.H2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16661 is a flaw in IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. It exists in the service processor mailbox interface and allows an attacker with authenticated service-level access to the Flexible Service Processor (FSP) to execute arbitrary code in the host firmware runtime. This grants full control over the managed system, leading to confidentiality, integrity, and availability impacts.

Detection Guidance

Detection requires checking the firmware version of IBM Power Systems running PowerVM Hypervisor. Compare installed versions against affected ranges: FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2. Use IBM tools like 'lsmcode' or 'fwversion' to verify firmware levels.

Impact Analysis

If exploited, this vulnerability allows an attacker to gain full control over the managed system. This could lead to unauthorized access to sensitive data, modification or deletion of critical system files, and disruption of system operations. The impact includes potential data breaches, system downtime, and loss of control over the affected infrastructure.

Compliance Impact

This vulnerability could lead to non-compliance with regulations like GDPR and HIPAA due to unauthorized access to sensitive data, potential data breaches, and loss of data integrity. Organizations may face legal penalties, reputational damage, and loss of customer trust if such a breach occurs.

Mitigation Strategies

Immediately update firmware to the latest non-vulnerable version via IBM Fix Central. Ensure authenticated service-level access to FSP is restricted. Monitor IBM advisories for additional guidance. No workarounds exist; updates are mandatory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16661. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart