CVE-2026-4932
Low
No strong exploitation signal.
CVSS base
4.2
MEDIUM
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
0.1%
0.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-331
Published 2026-07-28 · modified 2026-08-26
CVSS breakdown
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | P | Physical |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | N | None |
| Availability | N | None |
Timeline
- 2026-07-28 — Published (NVD)
- 2026-08-26 — Last modified (NVD)
Description
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.