What is CVE-2026-16687?
This CVE identifies a critical vulnerability in the ASMI web interface of specific IBM Power Systems Firmware versions. An unauthenticated attacker with network access can send a malformed request to the FSP, leading to arbitrary code execution. Affected versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 must be patched immediately.
Azərbaycanca: Bu CVE, IBM Power Systems Firmware-in müəyyən versiyalarında ASMI veb interfeysində aşkar edilmiş kritik bir boşluqdur. Şəbəkəyə çıxışı olan autentifikasiya olunmamış təcavüzkar, xüsusi hazırlanmış zərərli sorğu göndərərək FSP (Flexible Service Processor) üzərində ixtiyari kod icrasına nail ola bilər. Təsirə məruz qalan sistemlərdə FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80 və FW950.00-FW950.H2 versiyaları dərhal yenilənməlidir.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Which IBM Power Systems Firmware versions are affected by CVE-2026-16687?
The affected versions are FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2.
Does exploiting CVE-2026-16687 require authentication?
No, this vulnerability can be exploited by an unauthenticated attacker with network access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.