IBM Power Systems Firmware: 17 Vulnerabilities Disclosed, Including Critical Flaws
Key findings • 17 IBM Power Systems Firmware vulnerabilities disclosed on August 19, 2026. • Multiple Critical and High severity flaws allow for arbitrary code execution and administrative co…

Key findings
- 17 IBM Power Systems Firmware vulnerabilities disclosed on August 19, 2026.
- Multiple Critical and High severity flaws allow for arbitrary code execution and administrative control.
- Key themes include BMC/FSP interfaces, ASMI web interface, and network boot vulnerabilities.
- Affected firmware versions span FW1120.00 down to FW950.H2 and OP940 series.
- CVE-2026-16835 and CVE-2026-16687 are rated Critical with CVSSv3 scores of 9.6.
On August 19, 2026, a significant batch of 17 vulnerabilities was disclosed for IBM Power Systems Firmware. These vulnerabilities, disclosed within a two-hour window, span a range of severities from High to Critical, with multiple flaws allowing for arbitrary code execution and administrative control over affected systems. The disclosures impact various firmware versions, including FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, and OP940.00 through OP940.a1.
A prominent theme among these vulnerabilities is the interface between the BMC/FSP (Baseboard Management Controller/Flexible Service Processor) and the host system. CVE-2026-17063, CVE-2026-16933, CVE-2026-17429, and CVE-2026-16930 all detail issues within this interface. Attackers with service account or root access to the BMC/FSP can leverage these flaws to disrupt host processor state, execute arbitrary code on the host system, and gain full control. CVE-2026-17494 specifically highlights arbitrary code execution on the host system via the BMC-host interface, while CVE-2026-19234 allows for arbitrary code execution through a crafted code update image during the host firmware boot process.
Another critical area of concern is the ASMI (Advanced System Management Interface) web interface. CVE-2026-18848 and CVE-2026-16828 describe vulnerabilities within the ASMI web interface. CVE-2026-18848 allows an attacker to lure a logged-in administrator to a crafted webpage to perform administrative operations, while CVE-2026-16828 enables an unauthenticated attacker to crash the ASMI web server, potentially leading to memory corruption. Even more severe is CVE-2026-16687, a Critical severity vulnerability where an unauthenticated attacker can execute arbitrary code on the service processor by sending a malformed request to the FSP via the ASMI web interface.
Several vulnerabilities focus on authentication bypass and unauthorized administrative operations. CVE-2026-16835, a Critical severity flaw, allows an unauthenticated attacker on the management network to bypass authentication for the FSP management network protocol and perform any administrative operation. Similarly, CVE-2026-16832, a High severity vulnerability, permits an attacker with authenticated HMC administrator access to execute arbitrary code on the service processor via the FSP management network protocol.
Other vulnerabilities include issues with network boot processes and NVRAM parsing. CVE-2026-18821 affects the hypervisor during network boot, allowing an unauthenticated attacker on the same network to send a malformed network boot request. CVE-2026-17042 involves a vulnerability in host firmware NVRAM parsing, where an attacker with root access to a guest partition can cause the host to crash by writing a specially crafted NVRAM image.
The batch also includes vulnerabilities related to privileged operations and information disclosure. CVE-2026-16938, a Medium severity vulnerability, concerns access controls over privileged system configuration operations on the FSP, allowing an authenticated administrator to place the system in an unrecoverable state. CVE-2026-19321, another Medium severity flaw, allows an attacker with service access to the service processor to leak hardware register contents that should be inaccessible.
The affected firmware versions span a wide range, indicating a broad impact across different generations of IBM Power Systems. The vulnerabilities were disclosed on August 19, 2026, and users are advised to consult IBM's security advisories for specific patch information and mitigation strategies. The sheer number and severity of these vulnerabilities underscore the importance of maintaining up-to-date firmware and adhering to secure configuration practices for IBM Power Systems.
This coordinated disclosure of 17 vulnerabilities highlights potential systemic weaknesses in the firmware's security architecture, particularly concerning BMC/FSP interfaces, ASMI web services, and network boot processes. Users of IBM Power Systems are urged to prioritize patching and review their security configurations to mitigate the risks posed by these critical and high-severity flaws. The broad range of affected versions suggests that a comprehensive update strategy is necessary for organizations relying on this infrastructure.