PatchSiren cyber security CVE debrief
CVE-2026-17091 IBM CVE debrief
IBM PowerVM Hypervisor is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory.
- Vendor
- IBM
- Product
- PowerVM Hypervisor
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-25
Who should care
IBM Power Systems administrators, security teams, and IT professionals responsible for managing and securing PowerVM environments, as well as operators and platform administrators, should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. IT professionals responsible for vulnerability management and security teams should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. This may involve coordinating with IBM support teams and applying compensating controls for exposed systems while remediation is scheduled and verified. Regular review and update of system configurations are also necessary to prevent similar vulnerabilities in the future. The affected personnel should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should implement compensating controls, such as network segmentation, and monitor system logs for suspicious activity. They should also review and update system configurations regularly to prevent similar vulnerabilities in the future. The vulnerability management team should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. They should review the vulnerability details and assess the risk to their organization. They should also ensure that the necessary patches or updates are applied to affected systems and that compensating controls are implemented where necessary. The security team should also be aware of this vulnerability and ensure that necessary measures are taken to protect the systems. They should review the vulnerability details and assess the risk to their organization. They should also ensure, a
Technical summary
The vulnerability exists in the PowerVM hypervisor call interface, allowing an attacker with root access to a guest partition to inject arbitrary data into hypervisor or partition memory. This can result in a system crash or memory corruption, leading to integrity and availability impacts. The affected systems include IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 across various IBM Power Systems, such as S1022, S1024, S1014, L1022, L1024, E1050, E1080, E1150, and others. Defenders should verify the affected systems and apply patches or updates accordingly.
Defensive priority
High priority, as successful exploitation results in an integrity and availability impact to the managed system.
Recommended defensive actions
- Apply the vendor-provided patches or updates to affected systems.
- Restrict access to the PowerVM hypervisor call interface.
- Monitor system logs for suspicious activity.
- Implement compensating controls, such as network segmentation.
- Regularly review and update system configurations.
Evidence notes
The vulnerability exists in IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Multiple CPEs are affected across various IBM Power Systems, including S1022, S1024, S1014, L1022, L1024, E1050, E1080, E1150, and others. The evidence is limited, and defenders should verify the affected systems and apply patches or updates accordingly.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-17091 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-17091
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-17091 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17091
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7283229
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.