IBM has patched two critical vulnerabilities in Power Systems Firmware, CVE-2026-16687 and CVE-2026-16835, both rated 9.6 on the CVSS scale. These flaws allow unauthenticated attackers to gain full control of managed systems, posing a significant risk to organizations. The vulnerabilities affect various versions of Server Firmware (FW1120, FW1110, FW1060, FW950) across Power9, Power10, and Power11 servers. No confirmed exploitation has been reported yet.
IBM recommends immediate firmware updates to address these issues and suggests protecting access to the Flexible Service Processor's network interface as an additional mitigation step.