Skip to content
Threat Feed
critical advisory

Critical RCE Vulnerability in IBM Power Systems Firmware ASMI

IBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.

CVE search metadata

CVE search record: CVE-2026-16687. Severity: critical. CVSS: 9.6. KEV: no. Product: Power Systems Firmware. Brief: Critical RCE Vulnerability in IBM Power Systems Firmware ASMI. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-power-asmi-rce/

IBM has disclosed a critical security vulnerability, identified as CVE-2026-16687, affecting the Advanced System Management Interface (ASMI) of various Power Systems firmware versions. The vulnerability, classified as a stack-based buffer overflow (CWE-121), stems from improper validation of input within the web interface of the Flexible Service Processor (FSP). An unauthenticated attacker with network access to the ASMI management interface can send a malformed request, leading to memory corruption. This allows for arbitrary code execution, granting the attacker full control over the managed hardware system. Given the nature of FSP access, successful exploitation results in total loss of confidentiality, integrity, and availability for the affected Power Systems server. The vulnerability affects firmware versions in the FW1120.00, FW1110.xx, FW1060.xx, and FW950.xx series.

Impact

Successful exploitation allows an unauthenticated attacker to execute code with the privileges of the FSP, effectively gaining total control over the physical server management functions. This level of access permits unauthorized monitoring, data exfiltration, permanent disabling of the system, or the ability to bypass operating system security controls. The vulnerability impacts enterprise environments utilizing IBM Power Systems for critical infrastructure and mission-critical workloads.

Recommendation

Prioritized, concrete actions for security and infrastructure teams:

  • Immediately identify all IBM Power Systems hardware within the environment and verify the currently installed firmware version against the affected releases (FW1120.00, FW1110.00-30, FW1060.00-80, FW950.00-H2).
  • Apply the vendor-provided firmware updates listed in the official IBM security bulletin (referenced below) as the primary remediation.
  • Implement network segmentation to restrict access to the ASMI/FSP management interfaces, ensuring they are only accessible from secure, authorized management networks or dedicated VLANs.
  • Disable public or wide-area network access to the FSP interface immediately.
  • Monitor logs for unusual HTTP traffic directed toward the ASMI/FSP management interface, particularly requests containing abnormally large payloads or non-standard characters, which may indicate attempted exploitation of CVE-2026-16687.

Immediate actions

Patch firmware per IBM security bulletin for CVE-2026-16687

IT Operations 24h

Mitigations

Restrict network access to ASMI management interfaces via firewall or VLAN isolation

immediate IT Operations

CVE-2026-16687