CVE-2026-18681: This Power System Buffer Overflow
IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Other sources
Power Systems Firmware is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Server Firmware (FSP)to a version that resolves this vulnerability.Fixed in FW1060.81(1060_184) - Upgrade
Upgrade
IBM Server Firmware (FSP)to a version that resolves this vulnerability.Fixed in FW1120.01(1120_167) - Upgrade
Upgrade
IBM Server Firmware (FSP)to a version that resolves this vulnerability.Fixed in FW1110.31(1110_134) - Upgrade
Upgrade
IBM Server Firmware (FSP)to a version that resolves this vulnerability.Fixed in FW950.H3(950_230)
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running the listed affected IBM Server Firmware levels are exposed if an attacker has authenticated administrator-level access to the Flexible Service Processor (FSP). The attack vector is adjacent network access, and no user interaction is required.
What level of access does an attacker need?
Exploitation requires authenticated administrator-level access to the FSP. The vulnerability is in the FSP firmware update process and can allow arbitrary code execution under specific conditions.
What impact could successful exploitation have?
Successful exploitation can result in arbitrary code execution and affect confidentiality, integrity, and availability.
How can I determine whether a system is affected?
Check the installed IBM Server Firmware version. The affected versions are FW1120.00; FW1110.00 through FW1110.30; FW1060.00 through FW1060.80; and FW950.00 through FW950.H2.