← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 18:44via CVEFeed

CVE-2026-18848 - Power System Cross-Site Request Forgery (CSRF)

Brief

CVE ID : CVE-2026-18848

Published : Aug. 19, 2026, 6:44 p. m.

  • 24 minutes ago

Description : IBM Server Firmware FW1120. 00, FW1110. 00 through FW1110. 30, FW1060. 00 through FW1060. 80, and FW950. 00 through FW950. H2 is affected by a vulnerability in the ASMI web interface.

An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system.

Severity: 8.3

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed