s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-19492

📛 CVE Title

This Power System update is being released to address

Description

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.

Overview

State
PUBLISHED
Assigner (CNA)
ibm
CVSS severity
LOW
CVSS score
CVSS 3.2 / 10 3.2 3.2 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Effective score
3.2 / 10 LOW source: CNA overview
CWE(s)
CWE-457
Reserved
2026-08-10
Published
2026-09-24 14:17 UTC
Last updated
2026-09-24 14:50 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19492.json

NVD / KEV / EPSS data refreshed 2026-09-25 04:39 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-86007
Assigner
ibm
Published
Sep 24, 2026, 2:17:15 PM
Updated
Sep 24, 2026, 2:50:57 PM
EUVD base score (CVSS 3.1)
3.2 / 10
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
EUVD-reported EPSS
0.0000
Vendors
IBM
Products
PowerVM Hypervisor (FW1060.00 ≤FW1060.81)
PowerVM Hypervisor (FW1120.00 ≤FW1120.01)
PowerVM Hypervisor (FW1110.00 ≤FW1110.31)
Aliases
GHSA-q2mh-hq2m-m2mm

ENISA description: IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
IBM PowerVM Hypervisor FW1120.00 (affected), FW1110.00 (affected), FW1060.00 (affected) —

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (10)

  • web:aviatrix.ai

    CISA adds four actively exploited vulnerabilities to KEV Catalog affecting Fortinet, Citrix NetScaler, Chromium V8, and Cisco systems requiring immediate remediation .

    2026-09-25 10:47 UTC
  • web:cvetodo.com

    CVE-2026-19492 is a CVSS 3.2 low-severity vulnerability in PowerVM Hypervisor. Full technical analysis, mitigations , and exploit status — updated in real time.

    2026-09-25 10:47 UTC
  • web:docs.netscaler.com

    Remediate CVE - 2026 -19490 For CVE - 2026 -19490 impacted NetScaler instances, the remediation is a single-step process and you need to upgrade the vulnerable NetScaler instances to a release and build that has the fix . In the GUI, under CVE Detection > Impacted Instances, select the instances and click Proceed to upgrade workflow.

    2026-09-25 10:47 UTC
  • web:nvd.nist.gov

    NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.

    2026-09-25 10:47 UTC
  • web:securityonline.info

    CVE - 2026 -19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.

    2026-09-25 10:47 UTC
  • web:support.citrix.com

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE - 2026 -19489 and CVE - 2026 -19490 The information on this page is being provided to you on an "AS IS" and "AS-AVAILABLE" basis. The issues described on this page may or may not impact your system (s). Cloud Software Group, Inc. and its subsidiaries (collectively, "Cloud SG") make no representations, warranties, or guarantees as to the ...

    2026-09-25 10:47 UTC
  • web:www.abdallaelmorsi.net

    CISA added CVE - 2026 -19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog on September 9, 2026 , after confirming active exploitation in the wild. This is an unauthenticated, remotely exploitable flaw, CVSS v4.0 score of 9.3, on internet-facing infrastructure that routinely handles SSL VPN, ICA Proxy, CVPN, and RDP Proxy traffic. If your ...

    2026-09-25 10:47 UTC
  • web:www.cyber.gc.ca

    AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE - 2026 -19490 and CVE - 2026 -19489 - Update 1

    2026-09-25 10:47 UTC
  • web:www.rapid7.com

    On August 19, 2026 , a security advisory was published for CVE - 2026 -19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.

    2026-09-25 10:47 UTC
  • web:www.rescana.com

    Citrix NetScaler ADC/Gateway CVE - 2026 -19490 is a critical authentication bypass added to CISA KEV on September 9, 2026 . Patch to fixed builds and complete forensic triage.

    2026-09-25 10:47 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-19492.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-19492",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T14:50:45.611946Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T14:50:57.288Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.01:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.01.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.31:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.31.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.81:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.81.0:*:*:*:*:*:*:*"
          ],
          "product": "PowerVM Hypervisor",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "FW1120.01",
              "status": "affected",
              "version": "FW1120.00",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "FW1110.31",
              "status": "affected",
              "version": "FW1110.00",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "FW1060.81",
              "status": "affected",
              "version": "FW1060.00",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.</p>"
            }
          ],
          "value": "IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 3.2,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-457",
              "description": "CWE-457 Use of Uninitialized Variable",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T14:17:15.907Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7289137"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>Customers with the products below should install FW1110.32(1110_138), FW1120.02(1120_171), or newer to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System E1180 (9080-HEU)</li></ol><p>Customers with the products below should install FW1110.32(1110_160), FW1120.02(1120_195), or newer to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System S1122 (9824-22A)</li><li>IBM Power System S1124 (9824-42A)</li><li>IBM Power System S1122s (9824-22B)</li><li>IBM Power System S1114 (9824-41B)</li><li>IBM Power System L1122 (9856-22H)</li><li>IBM Power System L1124 (9856-42H)</li><li>IBM Power System E1150 (9043-MRU)</li></ol><p>Customers with the products below should install FW1120.02(1120_195), or newer to remediate this vulnerability.</p><p>Power 11</p><ol><li>IBM Power System S1112 (9242-21B, 9242-21T)</li></ol><p><br/>Customers with the products below should install FW1060.82(1060_189), or newer to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System E1080 (9080-HEX)</li></ol><p>Customers with the products below should install\u00a0 FW1060.82(1060_199), or newer to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System S1022 (9105-22A)</li><li>IBM Power System S1024 (9105-42A)</li><li>IBM Power System S1022s (9105-22B)</li><li>IBM Power System S1014 (9105-41B)</li><li>IBM Power System L1022 (9786-22H)</li><li>IBM Power System L1024 (9786-42H)</li><li>IBM Power System E1050 (9043-MRX)</li><li>IBM Power System S1012 (9028-21B)</li></ol><p><em>The images mentioned above can be located at IBM Fix Central : </em><a href=\"https://www.ibm.com/support/fixcentral/\" rel=\"noopener noreferrer nofollow\"><em>https://www.ibm.com/support/fixcentral/</em></a></p>"
            }
          ],
          "value": "Customers with the products below should install FW1110.32(1110_138), FW1120.02(1120_171), or newer to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System E1180 (9080-HEU)\n\n\nCustomers with the products below should install FW1110.32(1110_160), FW1120.02(1120_195), or newer to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System S1122 (9824-22A)\n  *  IBM Power System S1124 (9824-42A)\n  *  IBM Power System S1122s (9824-22B)\n  *  IBM Power System S1114 (9824-41B)\n  *  IBM Power System L1122 (9856-22H)\n  *  IBM Power System L1124 (9856-42H)\n  *  IBM Power System E1150 (9043-MRU)\n\n\nCustomers with the products below should install FW1120.02(1120_195), or newer to remediate this vulnerability.\n\n\n\nPower 11\n\n  *  IBM Power System S1112 (9242-21B, 9242-21T)\n\n\n\nCustomers with the products below should install FW1060.82(1060_189), or newer to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System E1080 (9080-HEX)\n\n\nCustomers with the products below should install\u00a0 FW1060.82(1060_199), or newer to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System S1022 (9105-22A)\n  *  IBM Power System S1024 (9105-42A)\n  *  IBM Power System S1022s (9105-22B)\n  *  IBM Power System S1014 (9105-41B)\n  *  IBM Power System L1022 (9786-22H)\n  *  IBM Power System L1024 (9786-42H)\n  *  IBM Power System E1050 (9043-MRX)\n  *  IBM Power System S1012 (9028-21B)\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/"
        }
      ],
      "title": "This Power System update is being released to address"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-19492",
    "datePublished": "2026-09-24T14:17:15.907Z",
    "dateReserved": "2026-08-10T17:48:24.977Z",
    "dateUpdated": "2026-09-24T14:50:57.288Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}