IBM Power Systems BMC/FSP firmware flaw enables host takeover and full partition control; impacts enterprise server infrastructure and can cause widespread disruption.
CVE-2026-16930
BMC/FSP firmware flaw allows code execution on IBM Power hosts and partitions.
Is CVE-2026-16930 being exploited?
Not confirmed. CVE-2026-16930 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.12% probability of exploitation in the next 30 days.
How severe is CVE-2026-16930?
CVE-2026-16930 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-16930?
Yes. A fix has been recorded for CVE-2026-16930. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-16930 affect?
CVE-2026-16930 affects IBM Power Systems BMC/FSP FW1120.00, IBM Power Systems BMC/FSP FW1110.00 - FW1110.30, IBM Power Systems BMC/FSP FW1060.00 - FW1060.80. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-16930?
Apply vendor firmware updates when available; restrict/segment BMC access; rotate BMC credentials; audit logs.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Authenticated attacker with service/root on the BMC/FSP can execute arbitrary code on the host, gaining full control of the host and all hosted partitions (RCE, data theft, disruption).
Immediate action required
- affectedFW1120.00
- affected>= FW1110.00 and <= FW1110.30
- affected>= FW1060.00 and <= FW1060.80
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.