What is CVE-2026-4936?
CVE-2026-4936 is a vulnerability in IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM where the use of persistent storage key seeds results in a reduced-strength AES key. This can be exploited by an attacker with access to the service processor or HMC. Affected versions span FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2; applying firmware updates and restricting access are recommended.
Azərbaycanca: CVE-2026-4936, IBM PowerVM Hypervisor Platform KeyStore (PKS) və virtual TPM proqram təminatında persistent storage key seed-in istifadəsi nəticəsində AES açarının gücünün azalmasına səbəb olan zəiflikdir. Bu, service processor və ya HMC-yə giriş əldə edən hücumçu tərəfindən istismar edilə bilər. FW1110.00-dan FW1110.20, FW1060.00-dan FW1060.71, FW950.00-dan FW950.H2-yə qədər olan versiyalar təsirlənir; müvafiq firmware yeniləmələri tətbiq edilməli və əlçatanlıq məhdudlaşdırılmalıdır.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Which components of IBM PowerVM Hypervisor are affected by CVE-2026-4936?
CVE-2026-4936 affects the IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM software.
What resources must an attacker gain access to in order to exploit CVE-2026-4936?
This vulnerability can be exploited by an attacker who gains access to the service processor or HMC.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.