Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-10025: IBM QRadar SIEM allows unauthorized access through XML data
CVE-2026-10025 · published 1 month ago
Summary
IBM QRadar SIEM versions 7.5 and 7.6 have a vulnerability that can allow attackers to access the system using specially crafted XML data. This could potentially allow unauthorized access to the system and its data. To mitigate this risk, IBM recommends updating to the latest version of QRadar.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | qradar | <= 7.6.0.1 |
| ibm | qradar_security_information_and_event_manager |
7.5.0 7.6.0 cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:* |
Original advisory text
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() functi...
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Severity
9.8
Critical
CVSS 3.1: 8.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-611XML External Entity (XXE)
Timeline
Published5 Aug 2026
Updated30 Aug 2026
First seen5 Aug 2026
Monitor software like this
Free during beta