PatchSiren cyber security CVE debrief
CVE-2026-17063 IBM CVE debrief
IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 are affected by a vulnerability in the interface between the BMC/FSP and the host system. This vulnerability allows an attacker with service account or root access to the BMC/FSP to access and disrupt host processor state, potentially affecting the managed system and all hosted partitions. The impact includes confidentiality and availability concerns. Administrators should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-08-19T20:17:12.307Z and has not been modified since then.
- Vendor
- IBM
- Product
- Power Systems Firmware
- CVSS
- HIGH 7.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-25
Who should care
IBM Power Systems administrators, security teams responsible for patch management, and personnel with access to BMC/FSP interfaces should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability affects IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80. It allows an attacker with service account or root access to the BMC/FSP to access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in confidentiality and availability impacts. The interface between the BMC/FSP and the host system is a critical component that requires secure access controls. Implementing patches or updates provided by IBM is crucial to address this vulnerability. Additionally, restricting access to the BMC/FSP and ensuring strong authentication mechanisms are in place can help mitigate the risk. Monitoring system logs for unusual activity that may indicate exploitation attempts is also recommended. This vulnerability has a high CVSS score of 7.9, emphasizing the need for prompt action. Consider implementing compensating controls such as network segmentation or additional security layers for affected systems. The CVE description indicates that IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 are affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in confidentiality and availability impacts. The vulnerability has been assessed as HIGH severity, with a CVSS score of 7.9, highlighting the importance of prioritizing patching this vulnerability due to its potential impact on system confidentiality and availability. The NVD entry is currently Analyzed, providing further details on the vulnerability assessment and potential impacts. Administrators of IBM Power Systems should prioritize patching this vulnerability due to its high CVSS score of 7.9 and potential impact on system confidentiality and availability. The evidence notes indicate that the CVE description provides information on the affected firmware versions and the potential impacts of the vulnerability. The CVE record was on
Defensive priority
Administrators of IBM Power Systems should prioritize patching this vulnerability due to its high CVSS score of 7.9 and potential impact on system confidentiality and availability.
Recommended defensive actions
- Apply patches or updates provided by IBM to address the vulnerability in the BMC/FSP interface.
- Restrict access to the BMC/FSP to only necessary personnel and ensure strong authentication mechanisms are in place.
- Monitor system logs for unusual activity that may indicate exploitation attempts.
- Consider implementing compensating controls such as network segmentation or additional security layers for affected systems.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE description indicates that IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 are affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-17063 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-17063
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-17063 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17063
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7283219
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.