2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16850 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16850

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16848 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16848

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16847 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16847

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16845 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16845

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16844 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16844

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16842 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16842

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16841 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16841

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16840 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16840

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16839 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16839

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an integer underflow in the IPv4 IP-options parser. CVSSv3.1 9.4 (CRITICAL)

CWECWE 125VNDIbmTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16834 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16834

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-16822 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16822

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation. CVSSv3.1 9.3 (CRITICAL)

CWECWE 295VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16707 — IBM: Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16707

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results CVSSv3.1 8.2 (HIGH)

CWECWE 125VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-16661 — IBM: An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16661

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the CVSSv3.1 8.2 (HIGH)

CWECWE 190VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
CRIT

CVE-2026-70496 — This grants excessive privileges beyond what is necessary for the operator's intended function, potentially

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70496

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster. CVSSv3.1 9.9 (CRITICAL)

CWECWE 250TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-18848 — IBM: Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18848

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system. CVSSv3.1 8.3 (HIGH)

CWECWE 352VNDIbmTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-19
2026-08-19 19:17Z
CRIT

CVE-2026-18315 — TrueBooker: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18315

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrit CVSSv3.1 9.8 (CRITICAL)

CWECWE 639VNDTruebookerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-17494 — IBM: An attacker with service access to the BMC can send a specially crafted command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17494

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. CVSSv3.1 8.2 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-17429 — IBM: Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17429

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can write arbitrary data to hardware control registers, allowing full control over the host system and all hosted partitions, resulti CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-17100 — Power: An attacker with authenticated service-level access to the BMC/FSP can exploit this vulnerability, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17100

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the BMC/FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confide CVSSv3.1 8.2 (HIGH)

CWECWE 787VNDPowerTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-17093 — IBM: Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17093

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiali CVSSv3.1 8.2 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-16930 — IBM: An attacker with service account or root access to the BMC/FSP can execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16930

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can execute arbitrary code on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 19:17Z
CRIT

CVE-2026-16835 — IBM: An unauthenticated attacker on the management network can bypass authentication and perform any administrative

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16835

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, CVSSv3.1 9.6 (CRITICAL)

CWECWE 295VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 19:17Z
HIGH

CVE-2026-16832 — IBM: An attacker with authenticated HMC administrator access can execute arbitrary code on the service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16832

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-19
2026-08-19 19:17Z
CRIT

CVE-2026-16687 — IBM: An unauthenticated attacker with network access can send the FSP a malformed request, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16687

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact. CVSSv3.1 9.6 (CRITICAL)

CWECWE 121VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 18:17Z
HIGH

CVE-2026-75149 — marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75149

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score