CVE•Published 2026-07-30•Modified 2026-08-10•1 article on news•5 live references•NVD data
CVE-2026-12943Ibm · Hardware_management_console
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
57
Exploit Prediction Scoring System · top 43% of all CVEs
Weaknesses (CWE)
Description
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Timeline
Published 2026-07-30
Modified 2026-08-10
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-12943Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Ibm Hardware Management Console"All exposed Ibm Hardware Management Console instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Hardware Management Console"HTTP body or banner mentions "Hardware Management Console" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-12943Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-12943Censys host search filtered to this CVE id.
grep.app
CVE-2026-12943Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-12943GitHub code search for direct mentions.
Google dork
"CVE-2026-12943" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.