Security Advisory
IBM Power system update for a service processor vulnerability
What Happened
IBM released a security bulletin and firmware update addressing CVE-2026-22796, a vulnerability in the Power system service processor involving handling of a maliciously crafted digitally signed file.
Why It Matters
The service processor sits below the operating system layer. A vulnerability here has implications beyond IBM i itself and affects the hardware platform's trust boundary, so it warrants firmware-level remediation, not just an OS-level PTF.
Recommended Actions
- Determine the firmware level on every Power system in scope
- Schedule the IBM-released firmware update through your normal hardware maintenance window
- Confirm HMC/BMC access used to apply firmware updates is itself access-controlled and MFA-protected