CVE-2026-1276General(ibm / linux_kernel)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • qradar_security_information_and_event_manager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernelqradar_security_information_and_event_manager

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 403-1903-20
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure2General2
2026-03-201
General1
Full discourse5 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-1276 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Ibm Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1276 #CVE-2026-1276 #CVE #Medium #Ibm #CyberSecurity #InfoSec https://t.co/SLOpHfvbFY

    Post summary

    A new CVE (CVE-2026-1276) targeting IBM products is announced with a medium severity score of 5.4, but no technical, exploit, or mitigation details are supplied.

    0000028
    108 followersView on X
  • NerdieNews@NewsNerdie
    General

    Inductive Automation Ignition Software vulnerability could allow malicious code execution with elevated permissions. Users urged to update. CVE-2026-31969: HTSlib CRAM decoder heap buffer overflow may enable arbitrary code execution or system crashes. CVE-2026-32743: PX4 Autopilot affected by stack-based buffer overflow from improper MAVLink log request handling. CVE-2026-1276: IBM QRadar SIEM is vulnerable to cross-site scripting, risking arbitrary JavaScript injection by authenticated users. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #BlueTeam #DFIR

    Post summary

    The post lists several CVEs with brief technical details and urges users to update their software, but not mentioning any active exploitation, PoC, or detailed patch guidance.

    0000029
    49 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1276 Cross-Site Scripting in IBM QRadar SIEM 7.5.0 Through Update Package 14 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1276 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet cites CVE‑2026‑1276, a cross‑site scripting flaw in IBM QRadar SIEM 7.5.0, and links to a vulnerability details page and notification, mentioning no PoC, exploit, or patch information.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1276 IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScri… https://www.cve.org/CVERecord?id=CVE-2026-1276

    Post summary

    An IBM QRadar SIEM vulnerability (CVE-2026-1276) is disclosed, affecting versions 7.5.0 through 7.5.0 Update Package 14 with an authenticated cross‑site scripting flaw; no PoC, exploit, patch, or active exploitation details are provided.

    0000082
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1276 - IBM QRadar SIEM Cross-Site Scripting Intel Report: https://ift.tt/FyXqTOs

    Post summary

    The alert reports IBM QRadar SIEM XSS vulnerability CVE-2026-1276 with a link to an Intel report but provides no exploit, patch, or active exploitation details.

    0000031
    335 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
Appibmqradar_security_information_and_event_manager7.5.0--
OSlinuxlinux_kernel---

Explore more