A vulnerability identified as critical has been detected in IBM QRadar up to 7.6.0.1/7.5.0 UP 15 Interim Fix 005. This issue affects the function
parseXmlPayload of the file q1labs_core.jar of the component Event Processing Pipeline. This manipulation causes xml external entity reference.
The identification of this vulnerability is CVE-2026-10025. It is possible to initiate the attack remotely. There is no exploit available.