PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93306 IBM CVE debrief

IBM Server Firmware has a vulnerability in its ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, impacting integrity and availability. Defenders should assess exposure and prioritize verifying the potential impact on ASMI management interfaces.

Vendor
IBM
Product
Server Firmware
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for IBM Server Firmware, ASMI management interfaces, and associated security teams should assess exposure and potential impact. This includes operators managing IBM Server Firmware and security teams overseeing vulnerability management and incident response.

Why it matters

Defenders should prioritize verifying exposure and assessing potential impact on ASMI management interfaces due to a vulnerability in IBM Server Firmware. The vulnerability could result in a sustained loss of access to the ASMI management interface if exploited repeatedly.

  • Potential loss of access to ASMI management interface
  • Possible memory corruption and error log generation
  • Denial-of-service attack against ASMI web interface

Technical summary

The ASMI web interface in IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is vulnerable to a denial-of-service attack. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on ASMI management interfaces.

Recommended defensive actions

  • Verify ASMI management interface exposure and assess potential impact
  • Review and implement recommended mitigations from IBM
  • Monitor ASMI logs for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from IBM may be necessary for comprehensive assessment. The vulnerability affects multiple firmware versions: FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3. Defenders should verify exposure and assess potential impact based on the specific firmware versions in use.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93306 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93306

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93306 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93306

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.