[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in IBM QRadar SIEM to execute arbitrary code, escalate privileges, conduct a denial of service attack, disclose information, and bypass security measures.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities to execute arbitrary code and escalate privileges.
- Who is affected
- Deployments of IBM QRadar SIEM are affected.
- Urgency
- Remediation is urgent due to high severity and confirmed exploitation.
- Action
- Apply available patches to mitigate the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch QRadar SIEM
Get an email when a new QRadar SIEM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1666
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2006-100020.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2006-100030.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2024-410730.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2024-564620.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2025-402520.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2025-687240.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2025-687410.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Moderate exploitation riskCVE-2026-15191.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all scored CVEs.
- Low exploitation riskCVE-2026-231910.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-234010.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesubuntu
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attackcert-bund
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilitiescert-bund
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilitiesubuntu
- medium[UPDATE] [medium] CPython: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilities allow denial of servicecert-bund
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)cert-fr-avis
- medium[UPDATE] [medium] Internet Systems Consortium BIND: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rightscert-bund
- highUSN-8620-2: Linux kernel (Azure FIPS) vulnerabilitiesubuntu
- unknownUSN-8615-2: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu
Recent advisories for IBM QRadar SIEM
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund · 2026-07-23
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31