{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-10025/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-10025"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["QRadar"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve-2026-10025","xxe","siem"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM QRadar versions 7.6.0.0 through 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 are susceptible to an XML External Entity (XXE) injection vulnerability. The flaw exists within the \u003ccode\u003eparseXmlPayload()\u003c/code\u003e function located in the \u003ccode\u003eq1labs_core.jar\u003c/code\u003e component of the event processing pipeline. This vulnerability is reachable when the QRadar system has at least one log source type configured to utilize XML-format property autodetection. An unauthenticated attacker can trigger this vulnerability by transmitting specially crafted XML-formatted syslog events to the standard syslog ingestion ports (UDP/TCP 514). Exploitation of this vulnerability allows for unauthorized access to local files on the system, potentially exposing sensitive configuration data or credentials stored within the QRadar environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this XXE vulnerability results in unauthorized disclosure of information (Confidentiality impact) and potentially impacts system availability (Availability impact) by disrupting the event processing pipeline. Organizations running affected versions of IBM QRadar and leveraging XML-based syslog ingestion are at risk of local file disclosure. Given the centralized nature of QRadar as a SIEM, the exposure of files could lead to a broader compromise of the monitored environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all QRadar instances running versions 7.6.0.0-7.6.0.1 or 7.5.0 (up to UP 15 Interim Fix 005).\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided security patches from IBM for CVE-2026-10025 immediately.\u003c/li\u003e\n\u003cli\u003eReview log source configurations to disable XML-format property autodetection if it is not strictly required for business operations.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual or highly anomalous XML-formatted syslog patterns directed at port 514 from untrusted segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T17:20:24Z","date_published":"2026-08-05T17:20:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-qradar-xxe/","summary":"IBM QRadar contains an XML External Entity (XXE) injection vulnerability in the event processing pipeline that allows unauthenticated attackers to read arbitrary files from the system.","title":"XXE Injection Vulnerability in IBM QRadar","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-qradar-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-10025","version":"https://jsonfeed.org/version/1.1"}