Junglewise Threat Intelligence

CVE-2026-16930: IBM Power Systems Firmware code execution in BMC/FSP interface

CVE-2026-16930 · Severity: high · CVSS 8.2 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems Firmware contains a vulnerability in the management interface between the BMC (Baseboard Management Controller) and the host system. An attacker with privileged access to the BMC can execute arbitrary code on the host system, gaining complete control over the system and all virtual partitions it runs. This could lead to full data compromise, system outages, and loss of business operations for organizations relying on these enterprise servers.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the BMC/FSP (Flexible Service Processor) interface of IBM Power Systems Firmware. An attacker with service account or root access to the BMC can execute arbitrary code with full privileges on the host system, affecting all hosted partitions. The attack requires local/adjacent access to the BMC management interface and elevated privileges on that interface. Patches are available: FW1110.31, FW1120.01, or FW1060.81 depending on the Power system generation. A system reboot is required after firmware updates to fully mitigate the vulnerability.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80

Timeline

  • 2026-08-19: disclosed: Publicly disclosed by IBM
  • 2026-08-19: patched: Patches available: FW1110.31, FW1120.01, FW1060.81 or newer

References

Related threats