CVE-2026-10538: Bmc Control-M/enterprise Manager

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.

Affected products

  • Bmc Control-M/enterprise Manager: from 9.0.20, before 9.0.21 (fixed in 9.0.21)
  • Bmc Control-M/server: from 9.0.20, before 9.0.21 (fixed in 9.0.21)

Published 2026-07-01. Last modified 2026-07-01.