CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] IBM QRadar SIEM: Multiple vulnerabilities

highknown exploitedpublic exploitCVE-2025-10263CVE-2025-13151CVE-2025-40026CVE-2025-48913CVE-2025-6170CVE-2025-66168
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in IBM QRadar SIEM to bypass security measures, escalate privileges, conduct a denial of service attack, disclose information, manipulate files, conduct a cross-site scripting attack, and execute arbitrary code.

CSIRTS triage

What
Multiple vulnerabilities in IBM QRadar SIEM enable bypass of security measures, privilege escalation, denial-of-service, information disclosure, file manipulation, cross-site scripting, and arbitrary code execution.
Who is affected
Organizations operating IBM QRadar SIEM deployments.
Urgency
Critical; actively exploited vulnerabilities in security infrastructure affecting detection and response capabilities.
Action
Apply all available security patches from IBM for QRadar SIEM immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch QRadar SIEM

Get an email when a new QRadar SIEM advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-27
Exploitation
Observed in the wild (CISA KEV)
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3043

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-10263coverage & exploitation statusNVD · CVE.org
CVE-2025-13151coverage & exploitation statusNVD · CVE.org
CVE-2025-40026coverage & exploitation statusNVD · CVE.org
CVE-2025-48913coverage & exploitation statusNVD · CVE.org
CVE-2025-6170coverage & exploitation statusNVD · CVE.org
CVE-2025-66168coverage & exploitation statusNVD · CVE.org
CVE-2025-71066coverage & exploitation statusNVD · CVE.org
CVE-2025-71089coverage & exploitation statusNVD · CVE.org
CVE-2026-10846coverage & exploitation statusNVD · CVE.org
CVE-2026-10879coverage & exploitation statusNVD · CVE.org
CVE-2026-12413coverage & exploitation statusNVD · CVE.org
CVE-2026-12505coverage & exploitation statusNVD · CVE.org
CVE-2026-14380coverage & exploitation statusNVD · CVE.org
CVE-2026-14474coverage & exploitation statusNVD · CVE.org
CVE-2026-14476coverage & exploitation statusNVD · CVE.org
CVE-2026-14739coverage & exploitation statusNVD · CVE.org
CVE-2026-15043coverage & exploitation statusNVD · CVE.org
CVE-2026-15308coverage & exploitation statusNVD · CVE.org
CVE-2026-15392coverage & exploitation statusNVD · CVE.org
CVE-2026-16243coverage & exploitation statusNVD · CVE.org
CVE-2026-16439coverage & exploitation statusNVD · CVE.org
CVE-2026-16441coverage & exploitation statusNVD · CVE.org
CVE-2026-23216coverage & exploitation statusNVD · CVE.org
CVE-2026-25749coverage & exploitation statusNVD · CVE.org
CVE-2026-31411coverage & exploitation statusNVD · CVE.org
CVE-2026-31419coverage & exploitation statusNVD · CVE.org
CVE-2026-31488coverage & exploitation statusNVD · CVE.org
CVE-2026-31692coverage & exploitation statusNVD · CVE.org
CVE-2026-33227coverage & exploitation statusNVD · CVE.org
CVE-2026-33416coverage & exploitation statusNVD · CVE.org
CVE-2026-33558coverage & exploitation statusNVD · CVE.org
CVE-2026-33845coverage & exploitation statusNVD · CVE.org
CVE-2026-33846coverage & exploitation statusNVD · CVE.org
CVE-2026-34197coverage & exploitation statusNVD · CVE.org
CVE-2026-3833coverage & exploitation statusNVD · CVE.org
CVE-2026-39304coverage & exploitation statusNVD · CVE.org
CVE-2026-40046coverage & exploitation statusNVD · CVE.org
CVE-2026-40466coverage & exploitation statusNVD · CVE.org
CVE-2026-41043coverage & exploitation statusNVD · CVE.org
CVE-2026-41044coverage & exploitation statusNVD · CVE.org
CVE-2026-41254coverage & exploitation statusNVD · CVE.org
CVE-2026-41411coverage & exploitation statusNVD · CVE.org
CVE-2026-41603coverage & exploitation statusNVD · CVE.org
CVE-2026-42009coverage & exploitation statusNVD · CVE.org
CVE-2026-42010coverage & exploitation statusNVD · CVE.org
CVE-2026-42011coverage & exploitation statusNVD · CVE.org
CVE-2026-42012coverage & exploitation statusNVD · CVE.org
CVE-2026-42013coverage & exploitation statusNVD · CVE.org

+12 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for IBM QRadar SIEM

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories