Skip to content
IBMCVE-2026-4932

IBM PowerVM Hypervisor: attacker could the Transparent Memory Encryption

Medium4.2CVE-2026-4932 · Published Jul 28, 2026 · updated Aug 26, 2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

IBM advisory

Affected versions

PackageAffectedFixed in
PowerVM Hypervisor
Product
>= FW1110.00, <= FW1110.20No fix yet
>= FW1060.00, <= FW1060.71No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-331

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: denial of service
High7.5Jul 28
IBM Aspera Faspex 5: insufficient session expiration
High8.2Jul 28
IBM WebSphere Application Server - Liberty: denial of service
High7.5Jul 28
IBM WebSphere Application Server: request smuggling
High8.7Jul 28
IBM WebSphere Application Server - Liberty: path traversal
High7.5Jul 28
IBM WebSphere Application Server: request smuggling
High8.7Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.