What is CVE-2026-16832?
CVE-2026-16832 is a critical vulnerability in the FSP management network protocol of IBM Power Systems Firmware. It allows an attacker with authenticated HMC administrator access to execute arbitrary code on the service processor in affected versions (FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2). Immediate firmware updates should be applied and HMC administrator access must be strictly restricted.
Azərbaycanca: CVE-2026-16832, IBM Power Systems Firmware-in FSP idarəetmə şəbəkə protokolunda aşkarlanmış kritik boşluqdur. Bu zəiflik autentifikasiya olunmuş HMC administratoru hüquqlarına malik təcavüzkara təsirə məruz qalan firmware versiyalarında (FW1120.00, FW1110.00 - FW1110.30, FW1060.00 - FW1060.80, FW950.00 - FW950.H2) servis prosessorunda ixtiyari kod icrasına imkan verir. Dərhal firmware yeniləməsi tətbiq edilməli və HMC administrator girişləri ciddi şəkildə məhdudlaşdırılmalıdır.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What conditions are required to exploit CVE-2026-16832?
Exploiting this vulnerability requires the attacker to have authenticated HMC administrator access.
Which firmware versions are affected by CVE-2026-16832?
Affected versions include FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.