CVE-2026-18681

Summary

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Affected Software

VendorProductVersion RangeStatus
IBMServer FirmwareFW1120.00affected
IBMServer FirmwareFW1110.00 <= FW1110.30affected
IBMServer FirmwareFW1060.00 <= FW1060.80affected
IBMServer FirmwareFW950.00 <= FW950.H2affected

Weaknesses

  • CWE-121: CWE-121 Stack-based Buffer Overflow

Workarounds

Protect administrator access to the FSP.  Install firmware images only from trusted sources.  Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References