---
id: CVE-2026-18821
title: >-
  IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00
  through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is
  affected by a vulnerability in partition firmware during network boot
summary: >-
  IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00
  through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is
  affected by a vulnerability in partition firmware during network boot. An
  unauthenticated…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
published: '2026-08-19'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18821'
references:
  - url: 'https://www.ibm.com/support/pages/node/7283232'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00196
epssPercentile: 0.08305
ingestedAt: '2026-08-23T03:41:35.286Z'
---

## Overview

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
