PatchSiren cyber security CVE debrief
CVE-2026-93306 IBM CVE debrief
IBM Server Firmware has a vulnerability in its ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, impacting integrity and availability. Defenders should assess exposure and prioritize verifying the potential impact on ASMI management interfaces.
- Vendor
- IBM
- Product
- Server Firmware
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for IBM Server Firmware, ASMI management interfaces, and associated security teams should assess exposure and potential impact. This includes operators managing IBM Server Firmware and security teams overseeing vulnerability management and incident response.
Why it matters
Defenders should prioritize verifying exposure and assessing potential impact on ASMI management interfaces due to a vulnerability in IBM Server Firmware. The vulnerability could result in a sustained loss of access to the ASMI management interface if exploited repeatedly.
- Potential loss of access to ASMI management interface
- Possible memory corruption and error log generation
- Denial-of-service attack against ASMI web interface
Technical summary
The ASMI web interface in IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is vulnerable to a denial-of-service attack. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on ASMI management interfaces.
Recommended defensive actions
- Verify ASMI management interface exposure and assess potential impact
- Review and implement recommended mitigations from IBM
- Monitor ASMI logs for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information from IBM may be necessary for comprehensive assessment. The vulnerability affects multiple firmware versions: FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3. Defenders should verify exposure and assess potential impact based on the specific firmware versions in use.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93306 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93306
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93306 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93306
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7289331
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.