{"api_version":"1","generated_at":"2026-07-28T20:34:44+00:00","cve":"CVE-2026-4932","urls":{"html":"https://cve.report/CVE-2026-4932","api":"https://cve.report/api/cve/CVE-2026-4932.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-4932","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-4932"},"summary":{"title":"This Power System update is being released to address Insufficient Entropy","description":"IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-07-28 19:17:36","updated_at":"2026-07-28 19:17:36"},"problem_types":["CWE-331","CWE-331 CWE-331 Insufficient Entropy"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.2","severity":"MEDIUM","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7280632","name":"https://www.ibm.com/support/pages/node/7280632","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-4932","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4932","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"PowerVM Hypervisor","version":"affected FW1110.00 FW1110.20 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"PowerVM Hypervisor","version":"affected FW1060.00 FW1060.71 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System E1180 (9080-HEU)\n\n\nCustomers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System S1122 (9824-22A)\n  *  IBM Power System S1124 (9824-42A)\n  *  IBM Power System S1122s (9824-22B)\n  *  IBM Power System S1114 (9824-41B)\n  *  IBM Power System L1122 (9856-22H)\n  *  IBM Power System L1124 (9856-42H)\n  *  IBM Power System E1150 (9043-MRU)\n\n\n\nCustomers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System E1080 (9080-HEX)\n\n\n\n\n\n\nCustomers with the products below should install  FW1060.72(1060_177)/FW1060.80(1060_185),  or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System S1022 (9105-22A)\n  *  IBM Power System S1024 (9105-42A)\n  *  IBM Power System S1022s (9105-22B)\n  *  IBM Power System S1014 (9105-41B)\n  *  IBM Power System L1022 (9786-22H)\n  *  IBM Power System L1024 (9786-42H)\n  *  IBM Power System E1050 (9043-MRX)\n  *  IBM Power System S1012 (9028-21B)","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-4932","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-28T18:46:42.963188Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-28T18:46:57.145Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:*","cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:*"],"product":"PowerVM Hypervisor","vendor":"IBM","versions":[{"lessThanOrEqual":"FW1110.20","status":"affected","version":"FW1110.00","versionType":"semver"},{"lessThanOrEqual":"FW1060.71","status":"affected","version":"FW1060.00","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.</p>"}],"value":"IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-331","description":"CWE-331 Insufficient Entropy","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-28T18:09:32.739Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7280632"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System E1180 (9080-HEU)</li></ol><p>Customers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System S1122 (9824-22A)</li><li>IBM Power System S1124 (9824-42A)</li><li>IBM Power System S1122s (9824-22B)</li><li>IBM Power System S1114 (9824-41B)</li><li>IBM Power System L1122 (9856-22H)</li><li>IBM Power System L1124 (9856-42H)</li><li>IBM Power System E1150 (9043-MRU)</li></ol><p><br/>Customers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System E1080 (9080-HEX)</li></ol><p></p><p>Customers with the products below should install  FW1060.72(1060_177)/FW1060.80(1060_185),  or newer and reboot the system to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System S1022 (9105-22A)</li><li>IBM Power System S1024 (9105-42A)</li><li>IBM Power System S1022s (9105-22B)</li><li>IBM Power System S1014 (9105-41B)</li><li>IBM Power System L1022 (9786-22H)</li><li>IBM Power System L1024 (9786-42H)</li><li>IBM Power System E1050 (9043-MRX)</li><li>IBM Power System S1012 (9028-21B)</li></ol>"}],"value":"Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System E1180 (9080-HEU)\n\n\nCustomers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System S1122 (9824-22A)\n  *  IBM Power System S1124 (9824-42A)\n  *  IBM Power System S1122s (9824-22B)\n  *  IBM Power System S1114 (9824-41B)\n  *  IBM Power System L1122 (9856-22H)\n  *  IBM Power System L1124 (9856-42H)\n  *  IBM Power System E1150 (9043-MRU)\n\n\n\nCustomers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System E1080 (9080-HEX)\n\n\n\n\n\n\nCustomers with the products below should install  FW1060.72(1060_177)/FW1060.80(1060_185),  or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System S1022 (9105-22A)\n  *  IBM Power System S1024 (9105-42A)\n  *  IBM Power System S1022s (9105-22B)\n  *  IBM Power System S1014 (9105-41B)\n  *  IBM Power System L1022 (9786-22H)\n  *  IBM Power System L1024 (9786-42H)\n  *  IBM Power System E1050 (9043-MRX)\n  *  IBM Power System S1012 (9028-21B)"}],"title":"This Power System update is being released to address Insufficient Entropy","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE</p>"}],"value":"NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE"}],"x_generator":{"engine":"ibm-cvegen"}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-4932","datePublished":"2026-07-28T18:09:32.739Z","dateReserved":"2026-03-26T19:43:02.211Z","dateUpdated":"2026-07-28T18:46:57.145Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-28 19:17:36","lastModifiedDate":"2026-07-28 19:17:36","problem_types":["CWE-331","CWE-331 CWE-331 Insufficient Entropy"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.5,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-28T18:46:42.963188Z","id":"CVE-2026-4932","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"4932","Ordinal":"1","Title":"This Power System update is being released to address Insufficie","CVE":"CVE-2026-4932","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"4932","Ordinal":"1","NoteData":"IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.","Type":"Description","Title":"This Power System update is being released to address Insufficie"}]}}}