What is CVE-2026-16828?
This critical vulnerability exists in the ASMI web interface of IBM Power Systems firmware, allowing an unauthenticated attacker on the management network to crash the ASMI web server, potentially leading to memory corruption. Affected versions range from FW950.00 to FW1120.00. Affected systems should be immediately updated to the latest firmware to mitigate the risk.
Azərbaycanca: Bu kritik zəiflik IBM Power Systems proqram təminatının ASMI veb interfeysində aşkarlanıb və idarəetmə şəbəkəsindəki autentifikasiya olunmamış hücumçunun ASMI veb serverini çökdürməsinə imkan verir. FW950.00-dən FW1120.00-ə qədər bir çox versiyalar təsirlənir, potensial yaddaş korrupsiyası riski daşıyır. Təsirlənən sistemlərin dərhal ən son proqram təminatı ilə yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Under what conditions can CVE-2026-16828 be exploited?
This vulnerability allows an unauthenticated attacker on the management network to crash the ASMI web server through the ASMI web interface of IBM Power Systems firmware.
What action should be taken to protect against CVE-2026-16828?
Affected systems should be immediately updated to the latest firmware. The vulnerability affects versions ranging from FW950.00 to FW1120.00.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.