CVE-2026-13477: IBM Qradar Security Information And Event Manager

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Affected products

  • IBM Qradar Security Information And Event Manager: version 7.5.0 only; version 7.6.0 only

Published 2026-08-05. Last modified 2026-08-10.