← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 18:48via CVEFeed

CVE-2026-16938 - Power System Missing Authorization

Brief

CVE ID : CVE-2026-16938

Published : Aug. 19, 2026, 6:48 p. m.

  • 20 minutes ago

Description : IBM Server Firmware FW1120. 00, FW1110. 00 through FW1110. 30, FW1060. 00 through FW1060. 80, and FW950. 00 through FW950. H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP.

An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation.

Successful exploitation results in an availability impact to the managed system.

Severity: 6.9

  • MEDIUM
Read more on CVEFeed