PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17414 IBM CVE debrief

IBM PowerVM Hypervisor is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition.

Vendor
IBM
Product
PowerVM Hypervisor
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-25
Advisory published
2026-08-19
Advisory updated
2026-08-25

Who should care

IBM PowerVM Hypervisor administrators, users with partitions configured for network boot, and security teams responsible for patch management and vulnerability remediation. Additionally, operators managing affected systems, platform owners, vulnerability management teams, and security teams overseeing remediation efforts should also be aware of this vulnerability and take necessary actions to mitigate its impact.

Technical summary

The vulnerability in IBM PowerVM Hypervisor affects partition firmware during network boot. An unauthenticated attacker with network access can prevent a partition from completing its boot sequence. If OS secure boot is not enabled, the attacker can also substitute the boot image, leading to a compromise of everything loaded by that partition. The issue impacts confidentiality, integrity, and availability.

Defensive priority

High priority to review and apply patches for affected IBM PowerVM Hypervisor versions, especially for partitions with OS secure boot not enabled.

Recommended defensive actions

  • Review and apply patches for affected IBM PowerVM Hypervisor versions.
  • Verify and enable OS secure boot where possible.
  • Monitor network boot activities for suspicious behavior.
  • Restrict network access to partition boot networks.
  • Perform inventory checks for affected systems and prioritize patching.

Evidence notes

The vulnerability affects IBM PowerVM Hypervisor versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. The issue is in partition firmware during network boot, allowing an unauthenticated attacker to prevent boot completion or substitute the boot image if OS secure boot is not enabled.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17414 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17414

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17414 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17414

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.