CVE-2025-1994: IBM Cognos Command Center

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.

Affected products

  • IBM Cognos Command Center: version 10.2.4.1 only; version 10.2.5 only

Published 2025-08-26. Last modified 2026-06-17.