SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-19492

LOW · CVSS 3.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

IBM PowerVM Hypervisor versions FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 are vulnerable due to a flaw in the hypervisor call interface that allows an attacker with root access to a guest partition to read limited hypervisor memory. This could lead to the exposure of sensitive data from the hypervisor or other guest partitions, posing a confidentiality risk, especially in multi-tenant environments where various operating systems may be running. Organizations utilizing these hypervisor versions in shared environments should prioritize addressing this vulnerability to mitigate potential data leaks.

CVE
CVE-2026-19492
Severity
LOW
CVSS
3.2
EPSS
0.11%

Original NVD Description

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.

Related CVEs

Other vulnerabilities affecting the same vendor(s)