Back

CRITICAL

IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability

Published Aug 5, 2026

Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

Affected products

Remediation

Vendor solution

IBM strongly encourages customers to update their systems promptly.

ProductVersionFixIBM QRadar SIEM 7.6.0  7.6.0.2 https://www.ibm.com/support/pages/node/7280199 IBM QRadar SIEM 7.5.0  7.5.0 UP15 IF05 Hotfix 20260715231428 https://www.ibm.com/support/pages/node/7282364

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Aug 5, 2026
Updated Aug 6, 2026
Reserved May 28, 2026
CISA Vulnrichment
Updated Aug 6, 2026
NVD
Status Analyzed
Modified Aug 10, 2026
Red Hat
Severity n/a
Public date n/a