CVE-2026-10539General

LOWCVSS 9.5 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-01); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-03: 1Mentions · 2026-07-31: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-31: 107-0107-0307-31
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-011
General1
2026-07-031
Disclosure1
2026-07-311
General1
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: #CVE-2026-10539 (CVSS 9.5) - unauthenticated command injection in #ControlM/Server can lead to full server compromise. More info at: https://nvd.nist.gov/vuln/detail/CVE-2026-10539. #Patch #Patch #Patch

    Post summary

    The tweet warns about CVE-2026-10539, a high‑severity unauthenticated command injection in Control M/Server that could lead to full server compromise, and references the NVD entry with a general patch notice.

    02000382
    7.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-10539: BMC Control-M/Server Unauthenticated Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04rtxtz0

    Post summary

    The post references CVE-2026-10539 as an unauthenticated command‑injection vulnerability in BMC Control‑M/Server but does not provide proof‑of‑concept, exploit code, evidence of active exploitation, or detailed mitigation information.

    0000048
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-10539 Command Injection Vulnerability in BMC Control-M/Server 9.0.20 Through 9.0.21.200 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-10539

    Post summary

    A command injection vulnerability has been reported in BMC Control‑M/Server 9.0.20 through 9.0.21.200, with limited details and no evidence of public exploits or patches.

    0000078
    4.1K followersView on X

Explore more