Sceawere

Vulnerability Detail

CVE-2026-16661UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM PowerVM FSP Mailbox Arbitrary Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
4h ago
Vendor
IBM
Product
PowerVM Hypervisor
Attack Type
CWE-190 Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-19T20:17:01.937Z",
  "pubdate": "2026-08-19T20:17:01.937Z",
  "executiveSummary": "A critical vulnerability exists within the service processor mailbox interface of the IBM PowerVM Hypervisor, enabling an attacker to achieve arbitrary code execution within the host firmware runtime. The vulnerability impacts specific firmware releases, notably IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Successful exploitation of this flaw grants an adversary complete administrative control over the managed system, leading to a total compromise of confidentiality, integrity, and availability. The attack vector requires authenticated service-level access to the Flexible Service Processor (FSP), meaning an unauthorized entity cannot exploit the flaw remotely without prior credential compromise or privileged positioning. Risk implications are severe, as arbitrary code execution in the host firmware runtime allows attackers to subvert hypervisor-level security controls, manipulate partition boundaries, and persistently compromise the underlying hardware management infrastructure. Organizations utilizing the affected firmware versions must apply vendor-supplied patches promptly and enforce strict access controls on service processor interfaces to mitigate unauthorized service-level interactions.",
  "technicalDetails": "The vulnerability resides in the service processor mailbox interface of the IBM PowerVM Hypervisor, a critical component responsible for facilitating communication and command processing between the Flexible Service Processor (FSP) and the host firmware runtime. The root cause stems from insufficient validation and improper handling of data passed through the mailbox interface, allowing malicious or malformed control messages to corrupt execution flow or inject executable instructions into memory spaces reserved for the host firmware runtime. Exploitation of this vulnerability requires an attacker to possess authenticated service-level access to the FSP. With the necessary service-level privileges, the attacker interacts with the service processor mailbox interface by supplying a crafted payload designed to leverage the interface's parsing flaws. Upon processing the malicious input, the FSP mailbox subsystem inadvertently executes the injected arbitrary code within the host firmware runtime context. Because the host firmware operates with the highest privilege level on the managed system, successful execution allows the attacker to bypass all hypervisor and operating system security mechanisms. The attack flow proceeds as follows: first, the adversary authenticates to the FSP using valid service-level credentials; second, the attacker issues a maliciously crafted command sequence via the mailbox interface; third, the vulnerable firmware subsystem processes the input without adequate bounds checking or sanitization; fourth, the arbitrary code is executed within the host firmware runtime. Post-exploitation impact includes full administrative control over the managed system, compromising the confidentiality, integrity, and availability of all hosted virtual machines and management functions. The vulnerability affects IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Network exposure is restricted by the requirement of authenticated service-level access, limiting direct exploitation vectors to internal management networks or compromised administrative sessions."
}
CVE-2026-16661: IBM PowerVM FSP Mailbox Arbitrary Code Execution (HIGH Severity, CVSS: 8.2) - Sceawere