Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19492— This Power System update is being released to address

Quick assessment

Affected
IBM PowerVM Hypervisor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IBM PowerVM Hypervisor FW1120.00 至 FW1120.01、FW1110.00 至 FW1110.31 以及 FW1060.00 至 FW1060.81 版本中,在虚拟机监控器调用接口存在一个漏洞。拥有来宾分区根(root)访问权限的攻击者可以读取有限量的虚拟机监控器内存,从而可能暴露属于虚拟机监控器或托管在同一系统中的其他来宾分区的敏感数据,造成机密性损失。攻击者无法控制返回哪些内存内容。在多租户环境中,来宾分区可能运行任意操作系统镜像,因此该漏洞尤其值得重视。

CVSS 3.2 · Low EPSS 0.11% · P1
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19492

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
This Power System update is being released to address
Source: CVE Program / CVE List V5
Vulnerability Description
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用未经初始化的变量
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
IBM PowerVM Hypervisor FW1120.00 ~ FW1120.01 cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-19492

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19492

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19492 (1)

Same Patch Batch · IBM · 2026-09-24 · 19 CVEs total

CVE-2026-81549 9.6 CRITICAL DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-82093 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-81552 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-81548 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-81547 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-81545 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-81539 8.8 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-77874 8.6 HIGH IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
CVE-2026-82094 7.1 HIGH DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-6544 6.2 MEDIUM Multiple Vulnerabilities in IBM Concert Software
CVE-2026-17413 5.1 MEDIUM This Power System update is being released to address
CVE-2026-17503 5.1 MEDIUM This Power System update is being released to address
CVE-2026-17504 5.1 MEDIUM This Power System update is being released to address
CVE-2026-77825 4.9 MEDIUM IBM ContextForge MCP Gateway is affected by path traversal
CVE-2026-18870 4.3 MEDIUM This Power System update is being released to address
CVE-2026-17511 3.4 LOW This Power System update is being released to address
CVE-2026-18857 3.4 LOW This Power System update is being released to address
CVE-2026-18104 3.3 LOW IBM Db2 Mirror for i is vulnerable to obtain sensitive information []

IV. Related Vulnerabilities

V. Comments for CVE-2026-19492

No comments yet


Leave a comment