PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17494 IBM CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:11.703Z and has not been modified since then. The vulnerability affects IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30, allowing an attacker with service access to the BMC to send a specially crafted command, enabling arbitrary code execution on the host system. This results in full control over the host system and all hosted partitions, impacting confidentiality, integrity, and availability. The CVSS score of 8.2 indicates high severity. Evidence is limited, so defenders should verify the affected scope and severity with IBM and the NVD. Additional review of system logs and monitoring is recommended to detect potential exploitation attempts. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Vendor
IBM
Product
Power Systems Firmware
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-22
Advisory published
2026-08-19
Advisory updated
2026-08-22

Who should care

System administrators and security teams responsible for IBM Power Systems Firmware, as well as organizations using these systems, should be aware of this vulnerability and take necessary defensive actions. Affected operators should review the vulnerability details and assess their exposure. Platform administrators should verify the firmware versions and plan for updates or mitigations. Vulnerability management teams should track this vulnerability and ensure that affected systems are remediated. Security teams should review compensating controls and monitoring to detect potential exploitation attempts.

Technical summary

The vulnerability affects IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system. This gives full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. The vulnerability has a high CVSS score of 8.2, indicating a high severity.

Defensive priority

High-priority defensive actions are required due to the high CVSS score of 8.2 and potential for arbitrary code execution.

Recommended defensive actions

  • Inventory and verify affected IBM Power Systems Firmware versions
  • Apply vendor patches or updates if available
  • Implement compensating controls to limit BMC access
  • Monitor for suspicious activity on the BMC and host system
  • Review and update incident response plans

Evidence notes

The CVE is based on information from IBM and the NVD. The vendor and product names are confirmed. The vulnerability affects IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30. Evidence is limited, and defenders should verify the affected scope and severity with IBM and the NVD. Additional review of system logs and monitoring is recommended to detect potential exploitation attempts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:11.703Z and has not been modified since then.