ReviewHigh

CVE-2026-16933

IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a)

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

CVSS
8.2
EPSS
0.12%
2.35% percentile
CISA KEV
Not listed
Published
2026.08.20
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 8.2

Vulnerability overview

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Affected product and versions

Product
IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a)
Affected versions
>= FW1120.00, >= FW1110.00 <= FW1110.30, >= FW1060.00 <= FW1060.80, >= FW950.00 <= FW950.H2, >= OP940.00 <= OP940.a1, >= OP940.00 <= OP940.81, >= fw1110.00 < fw1110.31, fw1120.00, >= fw1060.00 < fw1060.81, >= fw950.00 < fw950.h3, >= op940 < op940.a2, >= op940 < op940.82
Fixed versions
Verify the fixed release separately for each affected product line

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a) and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-190