CVE-2026-16687
Received Received - Intake

IBM Power Systems Firmware Code Execution Vulnerability

Vulnerability report for CVE-2026-16687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm power_systems_firmware fw1120.00
ibm power_systems_firmware From fw1110.00 (inc) to fw1110.30 (inc)
ibm power_systems_firmware From fw1060.00 (inc) to fw1060.80 (inc)
ibm power_systems_firmware From fw950.00 (inc) to fw950.h2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in IBM Power Systems Firmware where an unauthenticated attacker with network access can send a malformed request to the FSP via the ASMI web interface. This leads to arbitrary code execution, giving the attacker full control over the managed system. It affects multiple firmware versions and results in confidentiality, integrity, and availability impacts.

Detection Guidance

Detecting this vulnerability requires checking the firmware version of IBM Power Systems. Use the ASMI web interface or system management tools to verify if the firmware matches affected versions (FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2). Network scanning tools may identify exposed FSP interfaces but cannot confirm the vulnerability directly.

Impact Analysis

An attacker could exploit this to gain full control over the affected IBM Power Systems, leading to unauthorized access, data theft, system manipulation, or disruption of services. This could result in significant operational, financial, and reputational damage depending on the system's role.

Compliance Impact

This vulnerability could lead to breaches of confidentiality and integrity, which are critical under GDPR and HIPAA. Non-compliance risks include fines, legal penalties, and loss of trust due to unauthorized data access or system compromise.

Mitigation Strategies

Immediately update the firmware to the latest non-vulnerable versions (FW1120.01, FW1110.31, FW1060.81, or FW950.H3). Restrict network access to the FSP interface by disabling unnecessary services or using firewalls. Monitor IBM's support page for additional guidance and patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart