PatchSiren cyber security CVE debrief
CVE-2026-17414 IBM CVE debrief
IBM PowerVM Hypervisor is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition.
- Vendor
- IBM
- Product
- PowerVM Hypervisor
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-25
Who should care
IBM PowerVM Hypervisor administrators, users with partitions configured for network boot, and security teams responsible for patch management and vulnerability remediation. Additionally, operators managing affected systems, platform owners, vulnerability management teams, and security teams overseeing remediation efforts should also be aware of this vulnerability and take necessary actions to mitigate its impact.
Technical summary
The vulnerability in IBM PowerVM Hypervisor affects partition firmware during network boot. An unauthenticated attacker with network access can prevent a partition from completing its boot sequence. If OS secure boot is not enabled, the attacker can also substitute the boot image, leading to a compromise of everything loaded by that partition. The issue impacts confidentiality, integrity, and availability.
Defensive priority
High priority to review and apply patches for affected IBM PowerVM Hypervisor versions, especially for partitions with OS secure boot not enabled.
Recommended defensive actions
- Review and apply patches for affected IBM PowerVM Hypervisor versions.
- Verify and enable OS secure boot where possible.
- Monitor network boot activities for suspicious behavior.
- Restrict network access to partition boot networks.
- Perform inventory checks for affected systems and prioritize patching.
Evidence notes
The vulnerability affects IBM PowerVM Hypervisor versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. The issue is in partition firmware during network boot, allowing an unauthenticated attacker to prevent boot completion or substitute the boot image if OS secure boot is not enabled.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-17414 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-17414
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-17414 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17414
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7283234
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.