SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17091

HIGH · CVSS 8.4 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects IBM PowerVM Hypervisor across several firmware versions, allowing an attacker with root access to a guest partition to exploit the hypervisor call interface. This can lead to arbitrary data injection into hypervisor or partition memory, potentially causing system crashes or memory corruption, which impacts both the integrity and availability of the managed system. Organizations utilizing affected versions of IBM PowerVM should prioritize patching to mitigate the risk of sustained availability issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17091
Severity
HIGH
CVSS
8.4
EPSS
0.12%

Original NVD Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)