Junglewise Threat Intelligence

CVE-2026-18681: IBM Power Systems Server Firmware stack-based buffer overflow in FSP

CVE-2026-18681 · Severity: medium · CVSS 6.8 · Published 2026-08-19

Vendors: IBM.

Executive brief

IBM Power Systems firmware, used for managing enterprise server hardware, contains a stack-based buffer overflow vulnerability in its firmware update process. An authenticated administrator with access to the FSP (Flexible Service Processor) management interface can execute arbitrary code, compromising server confidentiality, integrity, and availability. This affects multiple IBM Power System models across several firmware versions.

Technical details

A stack-based buffer overflow (CWE-121) exists in the FSP firmware update process used by IBM Power Systems. The vulnerability is triggered during firmware image processing and requires authenticated administrator-level access to the FSP management interface to exploit. The attack vector is adjacent network (AV:A) with no user interaction required. Successful exploitation allows arbitrary code execution with the privileges of the FSP, impacting confidentiality, integrity, and availability. Patches are available for affected firmware versions (FW1120.01+, FW1110.31+, FW1060.81+, FW950.H3+).

Affected products

  • IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2

Timeline

  • 2026-08-15: disclosed

References