top of page
perceptive_background_267k.jpg

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allo…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 20:07:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Critical Infrastructure, Zero-Day Vulnerabilities

CVE-2026-12943 affects IBM Hardware Management Console (HMC) versions V10.3.1050.0 through V10.3.1064.0 and V11.1.1110.0 through V11.1.1112.0 used in IBM Power environments, including HMC and Novalink systems. The vulnerability allows an unauthenticated remote user to execute arbitrary commands with elevated privileges. The root cause is improper validation of user-supplied input, a classic input validation weakness. Given that no authentication is required and the attacker gains elevated privileges, this represents a critical attack surface for IBM Power infrastructure. Successful exploitation could lead to full system compromise, data exfiltration, or disruption of managed Power systems. IBM has published an advisory with remediation guidance. Organizations running affected HMC versions should prioritize patching immediately.

Technical details

Mitigation steps:

Affected products:

IBM HMC V10.3.1050.0
IBM HMC V10.3.1064.0
IBM HMC V11.1.1110.0
IBM HMC V11.1.1112.0
IBM Novalink

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page