# CVE-2026-17097

## Summary

- **CVE ID:** CVE-2026-17097
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H)
- **CWE:** CWE-129
- **Published:** Aug 19, 2026
- **Last Modified:** Aug 20, 2026

## Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

## Affected Products

- IBM — PowerVM Hypervisor (FW1120.00)
- IBM — PowerVM Hypervisor (FW1110.00)
- IBM — PowerVM Hypervisor (FW1060.00)
- IBM — PowerVM Hypervisor (FW950.00)

## References

- [CNA](https://www.ibm.com/support/pages/node/7283231)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._