CVE-2026-14971: IBM Powervm Novalink

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.

Affected products

  • IBM Powervm Novalink: version 2.2.0 only; version 2.2.1 only; version 2.2.1.1 only; version 2.3.0 only; version 2.3.0.1 only; version 2.3.1 only; …

Published 2026-07-17. Last modified 2026-08-11.