VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202608-8571 CVE-2026-63041 Apache Software Foundation of APISIX Vulnerability in relying on untrusted input for security decisions in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. 3.18.0 We recommend that you upgrade to .- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8039 CVE-2026-4937 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to entropy deficiency in multiple products such as the above. CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested. - No rewriting will occur to the information handled by the software. - The software will not stop
VAR-202608-7751 CVE-2026-4936 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to entropy deficiency in multiple products such as the above. CVSS V2: -
CVSS V3: 5.1
Severity: MEDIUM
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data. - No rewriting will occur to the information handled by the software. - The software will not stop
VAR-202608-8504 CVE-2026-18821 IBM of Power System E1050 (9043-MRX) Firmware Out-of-bounds write vulnerabilities in multiple products, including CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7793 CVE-2026-17414 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to input confirmation in multiple products such as CVSS V2: -
CVSS V3: 8.1
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8311 CVE-2026-17097 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to array index validation in multiple products such as CVSS V2: -
CVSS V3: 7.3
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system. IPL Initialization may be required. • Some of the information handled by the software may be rewritten. • The software may completely shut down
VAR-202608-8575 CVE-2026-17091 IBM of Power System E1050 (9043-MRX) Firmware Integer overflow vulnerability in multiple products, including CVSS V2: -
CVSS V3: 8.4
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system. As a result, the entire platform may be affected. • All information handled by the software may be overwritten. • The software may be completely shut down
VAR-202608-6747 CVE-2026-17042 IBM of IBM POWER HARDWARE MANAGEMENT CONSOLE (7063-CR2)  Out-of-bounds read vulnerability in multiple firmware and other products CVSS V2: -
CVSS V3: 7.3
Severity: HIGH
IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system. This condition is transmitted through the service processor. • Some of the information handled by the software may be rewritten. • The software may completely shut down
VAR-202608-8076 CVE-2026-17028 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to out-of-bounds reading in multiple products, including CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact. - No information handled by the software will be rewritten. - The software may completely shut down
VAR-202608-7004 CVE-2026-16933 IBM of IBM POWER HARDWARE MANAGEMENT CONSOLE (7063-CR2)  Integer overflow vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 8.2
Severity: HIGH
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. This has significant implications for confidentiality, integrity, and availability.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8321 CVE-2026-16707 IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to out-of-bounds reading in multiple products, including CVSS V2: -
CVSS V3: 8.2
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system. An attacker with authenticated service level access can exploit this vulnerability. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7280 CVE-2026-16661 IBM of Power System E1050 (9043-MRX) Firmware Integer overflow vulnerability in multiple products, including CVSS V2: -
CVSS V3: 8.2
Severity: HIGH
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system. An attacker with authenticated service level access rights can... - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7787 CVE-2026-18848 IBM of IBM Power System E1080 (9080-HEX) Cross-site request forgery vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 8.3
Severity: HIGH
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system. FSP Administrative operations can be performed silently above. This may affect the confidentiality, integrity, and availability of the managed systems.- Some of the information handled by the software may be leaked to external parties. - All of the information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7526 CVE-2026-18681 IBM of IBM Power System E1080 (9080-HEX) Stack-based buffer overflow vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 6.8
Severity: MEDIUM
IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8532 CVE-2026-17429 IBM of IBM POWER HARDWARE MANAGEMENT CONSOLE (7063-CR2)  Vulnerabilities related to unauthorized authentication in multiple products, such as firmware CVSS V2: -
CVSS V3: 8.1
Severity: HIGH
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can write arbitrary data to hardware control registers, allowing full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. - All of the information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7795 CVE-2026-17100 IBM of IBM POWER HARDWARE MANAGEMENT CONSOLE (7063-CR2)  Vulnerabilities related to out-of-bounds writes in multiple firmware and other products CVSS V2: -
CVSS V3: 8.2
Severity: HIGH
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the BMC/FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system. An attacker with authenticated service level access rights can... - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8640 CVE-2026-17093 IBM of IBM POWER HARDWARE MANAGEMENT CONSOLE (7063-CR2)  Stack-based buffer overflow vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 8.2
Severity: HIGH
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system. An attacker with service-level access rights could... - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-8079 CVE-2026-16938 IBM of IBM Power System E1080 (9080-HEX) Vulnerabilities related to lack of authentication in multiple products, such as firmware CVSS V2: -
CVSS V3: 6.9
Severity: MEDIUM
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system. • Some of the information handled by the software may be rewritten. • The software may completely shut down
VAR-202608-7277 CVE-2026-16835 IBM of IBM Power System E1080 (9080-HEX) Certificate verification vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 9.6
Severity: CRITICAL
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. This includes controlling the power state of partitions, changing configurations, and console access across all host partitions. As a result, there is a significant impact on the confidentiality, integrity, and availability of managed systems.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down
VAR-202608-7537 CVE-2026-16832 IBM of IBM Power System E1080 (9080-HEX) Stack-based buffer overflow vulnerability in multiple products, including firmware CVSS V2: -
CVSS V3: 8.4
Severity: HIGH
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact. This has serious implications for confidentiality, integrity, and availability.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down