CVE-2026-18681
Received Received - Intake

IBM Server Firmware FSP Arbitrary Code Execution

Vulnerability report for CVE-2026-18681, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm server_firmware fw1120.00
ibm server_firmware From fw1110.00 (inc) to fw1110.30 (inc)
ibm server_firmware From fw1060.00 (inc) to fw1060.80 (inc)
ibm server_firmware From fw950.00 (inc) to fw950.h2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18681 is a stack-based buffer overflow vulnerability in the FSP firmware update process of IBM Power Systems Firmware. It allows an attacker with authenticated administrator-level access to the FSP to execute arbitrary code under specific conditions, potentially impacting confidentiality, integrity, and availability.

Detection Guidance

Detecting this vulnerability requires checking the firmware version of IBM Power Systems. Compare your current firmware version against the affected versions listed: FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, and FW950.00-FW950.H2. Use the FSP management interface or IBM tools to verify the firmware version.

Impact Analysis

This vulnerability can lead to arbitrary code execution by an attacker with admin access, resulting in potential data breaches, system manipulation, or service disruption. It may cause loss of confidentiality, integrity, and availability of the affected IBM Power Systems.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations must mitigate this risk to maintain compliance with data protection and security standards.

Mitigation Strategies

Immediately update the firmware to the latest patched versions: FW1120.01(1120_167) or newer for Power 11 systems, FW1060.81(1060_184) or newer for Power 10 systems, and FW950.H3(950_230) or newer for Power 9 systems. Ensure administrator access to the FSP is restricted and firmware is only installed from trusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18681. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart