ID

VAR-202608-8504


CVE

CVE-2026-18821


TITLE

IBM of Power System E1050 (9043-MRX) Firmware Out-of-bounds write vulnerabilities in multiple products, including

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371

DESCRIPTION

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact. - All information handled by the software may be overwritten. - The software may completely shut down

Trust: 1.62

sources: NVD: CVE-2026-18821 // JVNDB: JVNDB-2026-030371

AFFECTED PRODUCTS

vendor:ibmmodel:power system s1112 \scope:eqversion:fw1120.00

Trust: 2.0

vendor:ibmmodel:power system s1112scope: - version: -

Trust: 1.6

vendor:ibmmodel:power system l1022 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1022 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1024 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1022 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1012 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s1014 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1012 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1014 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1050 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1022s \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1022s \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e1050 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1024 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system s1022 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1024 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system l1024 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system l1024scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1022sscope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1122sscope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1024scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1124scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e980scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1124scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1050scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1080scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1122scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1022scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1114scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1180scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1012scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1122scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1150scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1014scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1022scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s914scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e950scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371 // NVD: CVE-2026-18821

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@us.ibm.com: CVE-2026-18821
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2026-18821
value: HIGH

Trust: 1.0

NVD: CVE-2026-18821
value: HIGH

Trust: 0.8

psirt@us.ibm.com: CVE-2026-18821
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 5.9
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2026-18821
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2026-18821
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371 // NVD: CVE-2026-18821 // NVD: CVE-2026-18821

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

problemtype:Out-of-bounds writing (CWE-787) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371 // NVD: CVE-2026-18821

PATCH

title:Security Bulletinurl:https://www.ibm.com/support/pages/node/7283232

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371

EXTERNAL IDS

db:NVDid:CVE-2026-18821

Trust: 2.6

db:JVNDBid:JVNDB-2026-030371

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371 // NVD: CVE-2026-18821

REFERENCES

url:https://www.ibm.com/support/pages/node/7283232

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-18821

Trust: 0.8

sources: JVNDB: JVNDB-2026-030371 // NVD: CVE-2026-18821

SOURCES

db:JVNDBid:JVNDB-2026-030371
db:NVDid:CVE-2026-18821

LAST UPDATE DATE

2026-08-27T23:55:24.853000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-030371date:2026-08-26T07:28:00
db:NVDid:CVE-2026-18821date:2026-08-25T20:40:39.927

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-030371date:2026-08-26T00:00:00
db:NVDid:CVE-2026-18821date:2026-08-19T20:17:13.603