TL;DR
IBM patched two critical Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835. Both score 9.6 on CVSS. Each lets an unauthenticated attacker gain full control of the managed system. IBM reports no exploitation in the wild.
- Product: IBM Power Systems Firmware
- Vulnerabilities: 2 flaws (CVE-2026-16687, CVE-2026-16835)
- Highest severity: 9.6 (Critical · CVSSv3)
- Worst impact: Power System Buffer Overflow
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-16687 | 9.6 | CWE-121 | — | Not exploited |
| CVE-2026-16835 | 9.6 | CWE-295 | — | Not exploited |
Why It Matters
Power Systems run core workloads for banks, telecoms, and governments. The Flexible Service Processor, or FSP, controls those servers at a low level. An IBM Power Systems Firmware flaw at that layer therefore carries steep risk.
Both bugs score 9.6 and need no credentials. An attacker on the right network can seize the whole machine. Because the FSP governs every hosted partition, the blast radius is large.
How the Attacks Work
Each flaw targets a different FSP entry point. The mechanisms differ, yet both end in full control of the managed system.
CVE-2026-16687 (CVSS 9.6)
This flaw lives in the ASMI web interface. An unauthenticated attacker sends the FSP a malformed request. That request triggers a stack-based buffer overflow (CWE-121). Arbitrary code execution follows, per IBM’s ASMI firmware advisory.
CVE-2026-16835 (CVSS 9.6)
This flaw sits in the FSP management network protocol. Improper certificate validation (CWE-295) lets an attacker bypass authentication. From there, the attacker runs any administrative operation, including partition power and console access. IBM details it in a second FSP protocol advisory.
Affected Versions
Both flaws hit Server Firmware FW1120, FW1110, FW1060, and FW950 branches. Power9, Power10, and Power11 servers are in scope. IBM does not publish install-count estimates for exposed systems.
Patch and Mitigation Steps
IBM urges customers to update firmware without delay. Install FW1120.01, FW1110.31, FW1060.81, or FW950.H3, depending on the model. Grab the images from IBM Fix Central. As a mitigation, protect access to the FSP’s network interface.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!