CVE-2026-16707
Received Received - Intake

IBM PowerVM Hypervisor Memory Access Vulnerability

Vulnerability report for CVE-2026-16707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1110.00 (inc) to FW950.H2 (inc)
ibm powervm_hypervisor fw1120.00
ibm powervm_hypervisor to fw1110.30 (inc)
ibm powervm_hypervisor to fw1060.80 (inc)
ibm powervm_hypervisor to fw950.h2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. An attacker with authenticated service-level access to the Flexible Service Processor (FSP) can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory. This compromises the host firmware boot stack and the hypervisor loaded afterward.

The vulnerability is classified under CWE-125 (Out-of-bounds Read) with a CVSS base score of 8.2, indicating high severity.

Detection Guidance

Detection requires checking the firmware version of IBM Power Systems. Use the FSP command line interface to run 'version' or check the system firmware via IBM Hardware Management Console (HMC). Compare versions against affected ranges: FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2.

Impact Analysis

Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system. Attackers can read or modify critical firmware memory regions, potentially leading to system compromise, data breaches, or service disruption.

Mitigation Strategies

Install the latest firmware updates provided by IBM: FW1110.31, FW1120.01, FW1060.81, or FW950.H3. Access updates via IBM Fix Central and apply them through the HMC or FSP. No workarounds exist; updating firmware is the only mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart