<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-10025 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-10025/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 05 Aug 2026 17:20:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-10025/feed.xml" rel="self" type="application/rss+xml"/><item><title>XXE Injection Vulnerability in IBM QRadar</title><link>https://feed.craftedsignal.io/briefs/2026-08-ibm-qradar-xxe/</link><pubDate>Wed, 05 Aug 2026 17:20:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ibm-qradar-xxe/</guid><description>IBM QRadar contains an XML External Entity (XXE) injection vulnerability in the event processing pipeline that allows unauthenticated attackers to read arbitrary files from the system.</description><content:encoded><![CDATA[<p>IBM QRadar versions 7.6.0.0 through 7.6.0.1 and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 are susceptible to an XML External Entity (XXE) injection vulnerability. The flaw exists within the <code>parseXmlPayload()</code> function located in the <code>q1labs_core.jar</code> component of the event processing pipeline. This vulnerability is reachable when the QRadar system has at least one log source type configured to utilize XML-format property autodetection. An unauthenticated attacker can trigger this vulnerability by transmitting specially crafted XML-formatted syslog events to the standard syslog ingestion ports (UDP/TCP 514). Exploitation of this vulnerability allows for unauthorized access to local files on the system, potentially exposing sensitive configuration data or credentials stored within the QRadar environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this XXE vulnerability results in unauthorized disclosure of information (Confidentiality impact) and potentially impacts system availability (Availability impact) by disrupting the event processing pipeline. Organizations running affected versions of IBM QRadar and leveraging XML-based syslog ingestion are at risk of local file disclosure. Given the centralized nature of QRadar as a SIEM, the exposure of files could lead to a broader compromise of the monitored environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all QRadar instances running versions 7.6.0.0-7.6.0.1 or 7.5.0 (up to UP 15 Interim Fix 005).</li>
<li>Apply the vendor-provided security patches from IBM for CVE-2026-10025 immediately.</li>
<li>Review log source configurations to disable XML-format property autodetection if it is not strictly required for business operations.</li>
<li>Monitor network traffic for unusual or highly anomalous XML-formatted syslog patterns directed at port 514 from untrusted segments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve-2026-10025</category><category>xxe</category><category>siem</category></item></channel></rss>