SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18821

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 are vulnerable during network boot, allowing unauthenticated attackers on the same network to execute arbitrary code in the partition firmware. This can compromise the confidentiality, integrity, and availability of the affected partition, although other partitions and the managed system remain unaffected. Organizations using these firmware versions, particularly those with partitions that perform network booting, should prioritize remediation to mitigate this high-severity vulnerability.

CVE
CVE-2026-18821
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

Related CVEs

Other vulnerabilities affecting the same vendor(s)