PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18084 BlackBerry CVE debrief

The CVE record describes an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, which allows Cross-Site Scripting (XSS). The vulnerability affects UEM 12.23.0 QF8 or earlier. The CVSS score is 8.6 with a High severity. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk of Cross-Site Scripting (XSS) attacks. The CVE record was published on 2026-07-28T17:16:37.960Z and has not been modified since then.

Vendor
BlackBerry
Product
UEM
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-28
Original CVE updated
2026-08-14
Advisory published
2026-07-28
Advisory updated
2026-08-14

Who should care

Organizations using BlackBerry Unified Endpoint Manager (UEM) 12.23.0 QF8 or earlier should be aware of this vulnerability and take necessary actions to mitigate the risk of Cross-Site Scripting (XSS) attacks. This includes reviewing and updating incident response plans, implementing additional security measures, and applying patches or updates provided by BlackBerry.

Technical summary

The CVE record describes an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, which allows Cross-Site Scripting (XSS). The vulnerability affects UEM 12.23.0 QF8 or earlier. The CVSS score is 8.6 with a High severity. This vulnerability can be exploited through Cross-Site Scripting (XSS) attacks, which can lead to unauthorized access or modifications to sensitive data.

Defensive priority

Organizations using BlackBerry UEM 12.23.0 QF8 or earlier should prioritize patching to prevent potential Cross-Site Scripting (XSS) attacks.

Recommended defensive actions

  • Apply patches or updates provided by BlackBerry to address the vulnerability in UEM 12.23.0 QF8 or earlier
  • Implement additional security measures to detect and prevent Cross-Site Scripting (XSS) attacks
  • Review and update incident response plans to include procedures for handling potential XSS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD details indicate an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, allowing Cross-Site Scripting (XSS). Affected versions include UEM 12.23.0 QF8 or earlier. Limited evidence is available on the exact scope of the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T17:16:37.960Z and has not been modified since then.