PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16707 IBM CVE debrief

IBM PowerVM Hypervisor is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. This vulnerability impacts the confidentiality, integrity, and availability of the managed system. The affected versions include FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Administrators should verify system configurations and review logs for suspicious mailbox activity.

Vendor
IBM
Product
PowerVM Hypervisor
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-25
Advisory published
2026-08-19
Advisory updated
2026-08-25

Who should care

IBM Power Systems administrators, security teams managing IBM infrastructure, and IT professionals responsible for PowerVM Hypervisor deployments should be aware of this vulnerability. These stakeholders need to assess their exposure, apply patches or mitigations, and monitor for potential exploitation attempts. Additionally, security teams should review compensating controls and ensure that monitoring and detection capabilities are in place for affected systems.

Technical summary

The vulnerability exists in the service processor mailbox interface of IBM PowerVM Hypervisor. An attacker with authenticated service-level access can send crafted mailbox messages to read or modify Hostboot memory, impacting the host firmware boot stack and subsequently loaded hypervisor. This could lead to a compromise of the hypervisor and potentially allow for lateral movement or escalation of privileges within the managed system.

Defensive priority

High priority due to potential for confidentiality, integrity, and availability impact.

Recommended defensive actions

  • Apply vendor patches for affected PowerVM Hypervisor versions.
  • Restrict access to the service processor mailbox interface.
  • Monitor for suspicious activity related to mailbox messages.
  • Verify and update inventory of affected systems.
  • Implement compensating controls for memory access.

Evidence notes

The vulnerability exists in IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Multiple CPEs are affected across various IBM Power Systems, including S1022, S1024, S1014, L1022, L1024, E1050, E1080, E1150, and others. Evidence is limited to vendor advisories and CVE details. Defenders should verify system configurations, review logs for suspicious mailbox activity, and monitor for indicators of compromise within the affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16707 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16707

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16707 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16707

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.