SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-18871

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing.

HIGH 7.3EPSS 0.11%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, resulting in an integrity and availability impact to the managed system.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
EPSS
0.11% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-121
Affected
ibm/power system s1122 \(9824-22a\) firmware · ibm/power system s1124 \(9824-42a\) firmware · ibm/power system s1122s \(9824-22b\) firmware · ibm/power system s1114 \(9824-41b\) firmware · ibm/power system l1122 \(9856-22h\) firmware · ibm/power system l1124 \(9856-42h\) firmware · ibm/power system e1150 \(9043-mru\) firmware · ibm/power system s1112 \(9242-21b\) firmware · ibm/power system s1112 \(9242-21t\) firmware · ibm/power system e1080 \(9080-hex\) firmware · ibm/power system s1022 \(9105-22a\) firmware · ibm/power system s1024 \(9105-42a\) firmware · ibm/power system s1022s \(9105-22b\) firmware · ibm/power system s1014 \(9105-41b\) firmware · ibm/power system l1022 \(9786-22h\) firmware · ibm/power system l1024 \(9786-42h\) firmware · ibm/power system e1050 \(9043-mrx\) firmware · ibm/power system s1012 \(9028-21b\) firmware · ibm/power system e1180 \(9080-heu\) firmware
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.