


Perceptive Security
SOC/SIEM Consultancy

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allo…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 20:07:35
Source:
nvd.nist.gov
Enterprise Applications, Critical Infrastructure, Zero-Day Vulnerabilities
CVE-2026-12943 affects IBM Hardware Management Console (HMC) versions V10.3.1050.0 through V10.3.1064.0 and V11.1.1110.0 through V11.1.1112.0 used in IBM Power environments, including HMC and Novalink systems. The vulnerability allows an unauthenticated remote user to execute arbitrary commands with elevated privileges. The root cause is improper validation of user-supplied input, a classic input validation weakness. Given that no authentication is required and the attacker gains elevated privileges, this represents a critical attack surface for IBM Power infrastructure. Successful exploitation could lead to full system compromise, data exfiltration, or disruption of managed Power systems. IBM has published an advisory with remediation guidance. Organizations running affected HMC versions should prioritize patching immediately.
Technical details
Mitigation steps:
Affected products:
IBM HMC V10.3.1050.0
IBM HMC V10.3.1064.0
IBM HMC V11.1.1110.0
IBM HMC V11.1.1112.0
IBM Novalink
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
