What is CVE-2026-16661?
A vulnerability in the service processor mailbox interface of IBM PowerVM Hypervisor allows an attacker with authenticated service-level access to the FSP to exploit the system. Affected versions include FW950.00 through FW950.H2, FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, and FW1120.00. It is recommended to apply the updates provided by the vendor immediately.
Azərbaycanca: IBM PowerVM Hypervisor-in xidmət prosessoru poçt interfeysində aşkar edilmiş bu boşluq, autentifikasiya olunmuş xidmət səviyyəli girişi olan təcavüzkara FSP üzərində təsir imkanı yaradır. FW950.00-FW950.H2, FW1060.00-FW1060.80, FW1110.00-FW1110.30 və FW1120.00 versiyaları təsirə məruz qalır. Dərhal vendor tərəfindən təqdim edilən yeniləmələri tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What level of access does an attacker need to exploit CVE-2026-16661?
To exploit this vulnerability, an attacker must have authenticated service-level access to the FSP.
Which firmware versions of IBM PowerVM Hypervisor are affected by CVE-2026-16661?
The affected versions are FW950.00 through FW950.H2, FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, and FW1120.00.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.