Skip to content
IBMCVE-2026-10025

IBM QRadar: XML external entity

High8.2CVE-2026-10025 · Published Aug 5, 2026 · updated Aug 10, 2026

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

IBM advisory

Affected versions

PackageAffectedFixed in
QRadar
Product
>= 7.6.0.0, <= 7.6.0.1No fix yet
>= 7.5.0, <= 7.5.0 UP 15 Interim Fix 005No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-611

More IBM advisories

All IBM
Advisory
IBM Langflow OSS: weak cryptography
High7.4Aug 5
IBM Langflow OSS: code injection
High8.1Aug 5
IBM Langflow OSS: code execution
High8.8Aug 5
IBM Langflow OSS: information disclosure
High7.1Aug 5
IBM Langflow OSS: code injection
High8.8Aug 5
IBM Langflow OSS: broken cryptography
High7.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.