CVE-2026-4932

MEDIUM

This Power System update is being released to address Insufficient Entropy

Title source: cna
STIX 2.1

Description

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7280632

Scores

CVSS v3 4.2
EPSS 0.0008
EPSS Percentile 0.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-331
Status published
Products (2)
IBM/PowerVM Hypervisor FW1060.00 - FW1060.71
IBM/PowerVM Hypervisor FW1110.00 - FW1110.20
Published Jul 28, 2026
Tracked Since Jul 29, 2026