High severity7.5NVD Advisory· Published Aug 19, 2026· Updated Aug 25, 2026
CVE-2026-18821
CVE-2026-18821
Description
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2
- Range: FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7283232nvdVendor Advisory
News mentions
2- IBM: 25 Vulnerabilities Across AIX, PowerVM, and Storage Disclosed TogetherVypr Intelligence · Aug 19, 2026
- IBM Power Systems Firmware: 17 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Aug 19, 2026