PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17091 IBM CVE debrief

IBM PowerVM Hypervisor is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory.

Vendor
IBM
Product
PowerVM Hypervisor
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-25
Advisory published
2026-08-19
Advisory updated
2026-08-25

Who should care

IBM Power Systems administrators, security teams, and IT professionals responsible for managing and securing PowerVM environments, as well as operators and platform administrators, should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. IT professionals responsible for vulnerability management and security teams should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. This may involve coordinating with IBM support teams and applying compensating controls for exposed systems while remediation is scheduled and verified. Regular review and update of system configurations are also necessary to prevent similar vulnerabilities in the future. The affected personnel should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should implement compensating controls, such as network segmentation, and monitor system logs for suspicious activity. They should also review and update system configurations regularly to prevent similar vulnerabilities in the future. The vulnerability management team should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. They should review the vulnerability details and assess the risk to their organization. They should also ensure that the necessary patches or updates are applied to affected systems and that compensating controls are implemented where necessary. The security team should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. They should review the vulnerability details and assess the risk to their organization. They should also ensure, a

Technical summary

The vulnerability exists in the PowerVM hypervisor call interface, allowing an attacker with root access to a guest partition to inject arbitrary data into hypervisor or partition memory. This can result in a system crash or memory corruption, leading to integrity and availability impacts. The affected systems include IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 across various IBM Power Systems, such as S1022, S1024, S1014, L1022, L1024, E1050, E1080, E1150, and others. Defenders should verify the affected systems and apply patches or updates accordingly.

Defensive priority

High priority, as successful exploitation results in an integrity and availability impact to the managed system.

Recommended defensive actions

  • Apply the vendor-provided patches or updates to affected systems.
  • Restrict access to the PowerVM hypervisor call interface.
  • Monitor system logs for suspicious activity.
  • Implement compensating controls, such as network segmentation.
  • Regularly review and update system configurations.

Evidence notes

The vulnerability exists in IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Multiple CPEs are affected across various IBM Power Systems, including S1022, S1024, S1014, L1022, L1024, E1050, E1080, E1150, and others. The evidence is limited, and defenders should verify the affected systems and apply patches or updates accordingly.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17091 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17091

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17091 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17091

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.