AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-10025

HIGH · CVSS 8.2 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 are vulnerable to an XML External Entity (XXE) injection due to improper handling of XML-formatted syslog events. This vulnerability allows unauthenticated attackers to exploit the event processing pipeline, potentially leading to data exposure or system compromise. Organizations using affected QRadar versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-10025
Severity
HIGH
CVSS
8.2
EPSS
0.35%

Original NVD Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)