CVEPublished 2026-08-19Modified 2026-08-251 article on news5 live referencesNVD data

CVE-2026-16835Ibm · Power_system_e1080_\(9080-hex\)_firmware

Vulnerability data via NVD (ingested)

CVSS v3.1
9.6
CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
14
Exploit Prediction Scoring System · top 86% of all CVEs
Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.

Timeline
Published 2026-08-19
Modified 2026-08-25

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (2)