CVE-2026-16707
Analyzed Analyzed - Analysis Complete

IBM PowerVM Hypervisor Memory Access Vulnerability

Vulnerability report for CVE-2026-16707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-25

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-25
Generated
2026-09-09
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 34 associated CPEs
Vendor Product Version / Range
ibm power_system_s1122_(9824-22a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122_(9824-22a)_firmware fw1120.00
ibm power_system_s1124_(9824-42a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1124_(9824-42a)_firmware fw1120.00
ibm power_system_s1122s_(9824-22b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122s_(9824-22b)_firmware fw1120.00
ibm power_system_s1114_(9824-41b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1114_(9824-41b)_firmware fw1120.00
ibm power_system_l1122_(9856-22h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1122_(9856-22h)_firmware fw1120.00
ibm power_system_l1124_(9856-42h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1124_(9856-42h)_firmware fw1120.00
ibm power_system_e1150_(9043-mru)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1150_(9043-mru)_firmware fw1120.00
ibm power_system_s1112_(9242-21b)_firmware fw1120.00
ibm power_system_s1112_(9242-21t)_firmware fw1120.00
ibm power_system_e1080_(9080-hex)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022_(9105-22a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1024_(9105-42a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022s_(9105-22b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1014_(9105-41b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1022_(9786-22h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1024_(9786-42h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1050_(9043-mrx)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1012_(9028-21b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1180_(9080-heu)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1180_(9080-heu)_firmware fw1120.00
ibm power_system_s922_(9009-22g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h922_(9223-22s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s914_(9009-41g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s924_(9009-42g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h924_(9223-42s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e950_(9040-mr9)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e980_(9080-m9s)_firmware From fw950.00 (inc) to fw950.h3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. An attacker with authenticated service-level access to the Flexible Service Processor (FSP) can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory. This compromises the host firmware boot stack and the hypervisor loaded afterward.

The vulnerability is classified under CWE-125 (Out-of-bounds Read) with a CVSS base score of 8.2, indicating high severity.

Detection Guidance

Detection requires checking the firmware version of IBM Power Systems. Use the FSP command line interface to run 'version' or check the system firmware via IBM Hardware Management Console (HMC). Compare versions against affected ranges: FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2.

Impact Analysis

Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system. Attackers can read or modify critical firmware memory regions, potentially leading to system compromise, data breaches, or service disruption.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's confidentiality requirements and HIPAA's security rules for protected health information. Compromised firmware boot stacks may allow attackers to bypass security controls, exposing personal or health data.

Mitigation Strategies

Install the latest firmware updates provided by IBM: FW1110.31, FW1120.01, FW1060.81, or FW950.H3. Access updates via IBM Fix Central and apply them through the HMC or FSP. No workarounds exist; updating firmware is the only mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart