CVE-2026-16687: IBM Power System e1080 (9080-Hex) Firmware
Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
Affected products
- IBM Power System e1080 (9080-Hex) Firmware: from fw1060.00, before fw1060.81 (fixed in fw1060.81)
- IBM Power System e1180 (9080-Heu) Firmware: from fw1110.00, before fw1110.31 (fixed in fw1110.31); version fw1120.00 only
- IBM Power System e950 (9040-MR9) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System e980 (9080-m9s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System h922 (9223-22s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System h924 (9223-42s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s914 (9009-41g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s922 (9009-22g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s924 (9009-42g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
Published 2026-08-19. Last modified 2026-08-25.