CVE-2026-17093: Power System Buffer Overflow

Published Aug 15, 2026
·
Updated

IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.

Other sources

Power Systems Firmware is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.

IBM

Affected Software

5 affected components
IBM Power Firmware<=FW1120.00
IBM Power Firmware<=FW1110.00 - FW1110.30
IBM Power Firmware<=FW1060.00 - FW1060.80
IBM Power Firmware<=FW950.00 - FW950.H2
IBM Power Firmware<=OP940.00 - OP940.a1 (Power9)OP940.00 - OP940.81 (Power HMC)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in FW1060.81(1060_184)
  2. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in FW1060.81(1060_191)
  3. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in FW1120.01(1120_190)
  4. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in FW950.H3(950_230)
  5. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in OP940.82
  6. Upgrade

    Upgrade IBM Power Firmware to a version that resolves this vulnerability.

    Fixed in OP940.a2

Event History

Aug 15, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 19, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
RemedyDescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Which firmware releases should be checked for exposure?

Affected releases are FW1120.00; FW1110.00 through FW1110.30; FW1060.00 through FW1060.80; FW950.00 through FW950.H2; OP940.00 through OP940.a1 for Power9; and OP940.00 through OP940.81 for Power HMC.

2

What level of access does an attacker need?

The attacker needs service-level access to the BMC or FSP. They must be able to supply specially crafted host firmware configuration data.

3

How far can compromise extend if exploitation succeeds?

Successful exploitation can compromise the host firmware boot stage and everything subsequently loaded by it. The resulting impact includes confidentiality, integrity, and availability effects on the managed system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203