ID

VAR-202608-7277


CVE

CVE-2026-16835


TITLE

IBM of IBM Power System E1080 (9080-HEX) Certificate verification vulnerability in multiple products, including firmware

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138

DESCRIPTION

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. This includes controlling the power state of partitions, changing configurations, and console access across all host partitions. As a result, there is a significant impact on the confidentiality, integrity, and availability of managed systems.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down

Trust: 1.62

sources: NVD: CVE-2026-16835 // JVNDB: JVNDB-2026-030138

AFFECTED PRODUCTS

vendor:ibmmodel:power system e980 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e980scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1180scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1080scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s914scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e950scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138 // NVD: CVE-2026-16835

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@us.ibm.com: CVE-2026-16835
value: CRITICAL

Trust: 1.0

OTHER: JVNDB-2026-030138
value: CRITICAL

Trust: 0.8

psirt@us.ibm.com: CVE-2026-16835
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 6.0
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-030138
baseSeverity: CRITICAL
baseScore: 9.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138 // NVD: CVE-2026-16835

PROBLEMTYPE DATA

problemtype:CWE-295

Trust: 1.0

problemtype:Illegal certificate verification (CWE-295) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138 // NVD: CVE-2026-16835

PATCH

title:Security Bulletinurl:https://www.ibm.com/support/pages/node/7283894

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138

EXTERNAL IDS

db:NVDid:CVE-2026-16835

Trust: 2.6

db:JVNDBid:JVNDB-2026-030138

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138 // NVD: CVE-2026-16835

REFERENCES

url:https://www.ibm.com/support/pages/node/7283894

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-16835

Trust: 0.8

sources: JVNDB: JVNDB-2026-030138 // NVD: CVE-2026-16835

SOURCES

db:JVNDBid:JVNDB-2026-030138
db:NVDid:CVE-2026-16835

LAST UPDATE DATE

2026-08-27T23:49:44.979000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-030138date:2026-08-26T07:14:00
db:NVDid:CVE-2026-16835date:2026-08-25T17:59:13.683

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-030138date:2026-08-26T00:00:00
db:NVDid:CVE-2026-16835date:2026-08-19T19:17:10.690