IBM Qradar
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Qradar.
By the Year
In 2026 there have been 3 vulnerabilities in IBM Qradar with an average score of 6.7 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 6.70 |
It may take a day or so for new Qradar vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Qradar Security Vulnerabilities
IBM QRadar 7.5-7.6 XXE via q1labs_core.jar (before 7.6.2)
CVE-2026-10025
8.2 - High
- August 05, 2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
XXE
IBM QRadar 7.5/7.6 Arbitrary Command Execution via Improper Input Validation (Vuln in 7.5.0 & 7.6.0
CVE-2026-13477
4.7 - Medium
- August 05, 2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
Shell injection
IBM QRadar 7.5.0 Backup Upload RCE via Malicious Archive
CVE-2024-56462
7.2 - High
- May 27, 2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.
Exposure of Backup File to an Unauthorized Control Sphere
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Qradar or by IBM? Click the Watch button to subscribe.