SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17093

HIGH · CVSS 8.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, and OP940.00 through OP940.81 are vulnerable due to improper parsing of host firmware configuration, allowing attackers with service-level access to compromise the boot stage of the firmware. This can lead to significant impacts on the confidentiality, integrity, and availability of the managed systems. Organizations using these firmware versions should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-17093
Severity
HIGH
CVSS
8.2
EPSS
0.11%

Original NVD Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)