[NEW] [high] IBM QRadar SIEM: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in IBM QRadar SIEM to bypass security measures, escalate privileges, conduct a denial of service attack, disclose information, manipulate files, conduct a cross-site scripting attack, and execute arbitrary code.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM QRadar SIEM enable bypass of security measures, privilege escalation, denial-of-service, information disclosure, file manipulation, cross-site scripting, and arbitrary code execution.
- Who is affected
- Organizations operating IBM QRadar SIEM deployments.
- Urgency
- Critical; actively exploited vulnerabilities in security infrastructure affecting detection and response capabilities.
- Action
- Apply all available security patches from IBM for QRadar SIEM immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch QRadar SIEM
Get an email when a new QRadar SIEM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3043
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-102630.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-131511.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-400260.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-489130.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-61700.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-661680.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-710660.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-710890.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108460.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108790.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] GnuTLS: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] vim: Vulnerability allows code executioncert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Red Hat Enterprise Linux (sssd, glib, c-ares): Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] IBM AIX and VIOS: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Red Hat Enterprise Linux (DBI, perl-GD): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Oracle Java SE: Multiple vulnerabilitiescert-bund
- unknownUSN-8661-4: Linux kernel vulnerabilitiesubuntu
- unknownUSN-8715-1: Linux kernel (Oracle) vulnerabilitiesubuntu
Recent advisories for IBM QRadar SIEM
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] IBM QRadar SIEM: Vulnerability enables disclosure of informationcert-bund · 2026-09-02
- high[UPDATE] [high] IBM QRadar SIEM: Multiple Vulnerabilitiescert-bund · 2026-08-12
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund · 2026-08-06
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund · 2026-07-29
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund · 2026-07-23
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03