Junglewise Threat Intelligence

CVE-2026-16835: IBM Power Systems firmware authentication bypass in FSP management protocol

CVE-2026-16835 · Severity: critical · CVSS 9.6 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems firmware contains a flaw in the FSP (Flexible Service Processor) management network protocol that allows an attacker on the management network to bypass authentication entirely. An unauthenticated attacker can seize complete administrative control of the managed system—power cycling partitions, altering system configuration, and accessing partition consoles—affecting confidentiality, integrity, and availability of hosted workloads. This is a severe threat to data center operations and security posture.

Technical details

The vulnerability is an improper certificate validation issue (CWE-295) in the FSP management network protocol. An unauthenticated attacker positioned on the management network can bypass authentication checks and perform any administrative operation on the managed system, including power state control, system configuration modification, and console access across all partitions. Attack vector is adjacent (management network), requires no authentication or user interaction, and has scope change—allowing an attacker to move laterally or affect multiple partitions. Patches have been released: FW1120.01, FW1110.31, FW1060.81, and FW950.H3 or newer depending on platform generation.

Affected products

  • IBM Power Systems Firmware FW950.00 through FW950.H2, FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, FW1120.00

Timeline

  • 2026-08-15: disclosed: Initial publication by IBM
  • 2026-08: patched: IBM released patches: FW1120.01, FW1110.31, FW1060.81, FW950.H3 or newer

References

Related threats