CVE-2026-10538: Bmc Control-M/enterprise Manager
High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.
Affected products
- Bmc Control-M/enterprise Manager: from 9.0.20, before 9.0.21 (fixed in 9.0.21)
- Bmc Control-M/server: from 9.0.20, before 9.0.21 (fixed in 9.0.21)
Published 2026-07-01. Last modified 2026-07-01.