
CVE-2026-23780 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to… https://www.cve.org/CVERecord?id=CVE-2026-23780
Post summary
The text announces a newly disclosed SQL injection vulnerability in BMC Control‑M/MFT 9.0.x, allowing authenticated attackers to exploit the debug API.


