CVE-2026-16938: IBM Power System e1080 (9080-Hex) Firmware
Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.
Affected products
- IBM Power System e1080 (9080-Hex) Firmware: from fw1060.00, before fw1060.81 (fixed in fw1060.81)
- IBM Power System e1180 (9080-Heu) Firmware: from fw1110.00, before fw1110.31 (fixed in fw1110.31); version fw1120.00 only
- IBM Power System e950 (9040-MR9) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System e980 (9080-m9s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System h922 (9223-22s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System h924 (9223-42s) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s914 (9009-41g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s922 (9009-22g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
- IBM Power System s924 (9009-42g) Firmware: from fw950.00, before fw950.h3 (fixed in fw950.h3)
Published 2026-08-19. Last modified 2026-08-25.