SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18871

HIGH · CVSS 7.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

IBM PowerVM Hypervisor versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 are vulnerable due to a flaw in host firmware configuration parsing that allows authenticated attackers to inject malicious configuration data. This can lead to crashes in the host firmware boot stack, potentially causing memory corruption and impacting the integrity and availability of the managed system. Organizations using these specific firmware versions should prioritize remediation to mitigate risks associated with this vulnerability.

CVE
CVE-2026-18871
Severity
HIGH
CVSS
7.3
EPSS
0.11%

Original NVD Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, resulting in an integrity and availability impact to the managed system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)