CVE-2026-16835
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.22%
- CWE
- CWE-295
- Published
- 2026-08-19
- Last modified
- 2026-08-22
Affected products
- IBM Power Systems Firmware
- IBM Power Systems Firmware
- IBM Power Systems Firmware
- IBM Power Systems Firmware
Weakness type
Related vulnerabilities
- CVE-2026-87608 — Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging so
- CVE-2026-66795 — Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)
- CVE-2026-78234 — Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users
- CVE-2026-85102 — Improper Certificate Validation in Quantum Security Gateway
- CVE-2026-32253 — Sunshine: Authentication bypass via improper client certificate validation
- CVE-2026-82180 — In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication polic
- CVE-2026-22093 — Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
- CVE-2026-13385 — An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows