CVE-2026-18085: Blackberry Unified Endpoint Manager

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

Affected products

  • Blackberry Unified Endpoint Manager: version 12.23.0 only; version 12.22.1 only

Published 2026-07-28. Last modified 2026-08-14.