CVE-2026-93306: IBM Power System e1080 (9080-Hex) Firmware
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Affected products
- IBM Power System e1080 (9080-Hex) Firmware: from fw1060.00, before fw1060.82 (fixed in fw1060.82)
- IBM Power System e1180 (9080-Heu) Firmware: from fw1110.00, before fw1110.32 (fixed in fw1110.32); from fw1120.00, before fw1120.02 (fixed in fw1120.02)
- IBM Power System e950 (9040-MR9) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System e980 (9080-m9s) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System h922 (9223-22s) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System h924 (9223-42s) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System s914 (9009-41g) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System s922 (9009-22g) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
- IBM Power System s924 (9009-42g) Firmware: from fw950.00, before fw950.h4 (fixed in fw950.h4)
Published 2026-09-25. Last modified 2026-09-30.