CVE-2026-16687 & CVE-2026-16835: IBM Power Firmware Flaws Give Full Control of Managed System
ID: 06f3f496-1f34-5c1f-aa55-f86dbb653bb9
STIX ID: report--06f3f496-1f34-5c1f-aa55-f86dbb653bb9
Feed Name: securityonline.info
This advisory details two critical (CVSS 9.6) IBM Power Systems Firmware vulnerabilities — CVE-2026-16687 (ASMI web interface stack-based buffer overflow enabling unauthenticated remote code execution) and CVE-2026-16835 (FSP protocol improper certificate validation allowing authentication bypass and administrative control) — affecting multiple firmware branches on Power9/Power10/Power11; IBM has released firmware updates and recommends immediate patching and restricting FSP network access, with no confirmed exploitation reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
