logo

CVE-2026-16687 & CVE-2026-16835: IBM Power Firmware Flaws Give Full Control of Managed System

ID: 06f3f496-1f34-5c1f-aa55-f86dbb653bb9

STIX ID: report--06f3f496-1f34-5c1f-aa55-f86dbb653bb9

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

Author: Do Son

...
...

This advisory details two critical (CVSS 9.6) IBM Power Systems Firmware vulnerabilities — CVE-2026-16687 (ASMI web interface stack-based buffer overflow enabling unauthenticated remote code execution) and CVE-2026-16835 (FSP protocol improper certificate validation allowing authentication bypass and administrative control) — affecting multiple firmware branches on Power9/Power10/Power11; IBM has released firmware updates and recommends immediate patching and restricting FSP network access, with no confirmed exploitation reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.