Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-10025: IBM QRadar SIEM allows unauthorized access through XML data

CVE-2026-10025 · published 1 month ago
Summary

IBM QRadar SIEM versions 7.5 and 7.6 have a vulnerability that can allow attackers to access the system using specially crafted XML data. This could potentially allow unauthorized access to the system and its data. To mitigate this risk, IBM recommends updating to the latest version of QRadar.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm qradar <= 7.6.0.1
ibm qradar_security_information_and_event_manager 7.5.0
7.6.0
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
Original advisory text
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() functi...
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Severity
9.8 Critical
CVSS 3.1: 8.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-611XML External Entity (XXE)
Timeline
Published5 Aug 2026
Updated30 Aug 2026
First seen5 Aug 2026
Sources
CVE-2026-10025 · MITRE
Monitor software like this
Free during beta