SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17494

HIGH · CVSS 8.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30 are vulnerable due to a flaw in the interface between the Baseboard Management Controller (BMC) and the host system. An attacker with service access to the BMC can execute arbitrary code on the host, potentially compromising the confidentiality, integrity, and availability of the system and its partitions. Organizations using affected firmware should prioritize remediation to mitigate the risk of unauthorized access and control.

CVE
CVE-2026-17494
Severity
HIGH
CVSS
8.2
EPSS
0.11%

Original NVD Description

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Related CVEs

Other vulnerabilities affecting the same vendor(s)