What is CVE-2026-16707?
A vulnerability exists in the service processor (FSP) mailbox interface of the IBM PowerVM Hypervisor. An attacker with authenticated service-level access to the FSP could exploit this by sending a specially crafted mailbox message. Affected firmware versions should be updated immediately.
Azərbaycanca: IBM PowerVM Hipervizorunun xidmət prosessoru (FSP) poçt qutusu interfeysində kritik zəiflik aşkarlanıb. FSP-ə autentifikasiya olunmuş xidmət səviyyəli girişi olan təcavüzkar xüsusi hazırlanmış poçt qutusu mesajı göndərərək sistemi ələ keçirə bilər. Təsirə məruz qalmış FW versiyalarını dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What level of access does an attacker need to exploit CVE-2026-16707?
To exploit this vulnerability, an attacker must have authenticated service-level access to the FSP.
What measure should be taken to protect against CVE-2026-16707?
Affected firmware versions should be updated immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.