PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18084 BlackBerry CVE debrief

The CVE record describes an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, which allows Cross-Site Scripting (XSS). The vulnerability affects UEM 12.23.0 QF8 or earlier. The CVSS score is 8.6 with a High severity. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk of Cross-Site Scripting (XSS) attacks. The CVE record was published on 2026-07-28T17:16:37.960Z and has not been modified since then.

Vendor
BlackBerry
Product
UEM
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-28
Original CVE updated
2026-08-14
Advisory published
2026-07-28
Advisory updated
2026-08-14

Who should care

Organizations using BlackBerry Unified Endpoint Manager (UEM) 12.23.0 QF8 or earlier should be aware of this vulnerability and take necessary actions to mitigate the risk of Cross-Site Scripting (XSS) attacks. This includes reviewing and updating incident response plans, implementing additional security measures, and applying patches or updates provided by BlackBerry.

Technical summary

The CVE record describes an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, which allows Cross-Site Scripting (XSS). The vulnerability affects UEM 12.23.0 QF8 or earlier. The CVSS score is 8.6 with a High severity. This vulnerability can be exploited through Cross-Site Scripting (XSS) attacks, which can lead to unauthorized access or modifications to sensitive data.

Defensive priority

Organizations using BlackBerry UEM 12.23.0 QF8 or earlier should prioritize patching to prevent potential Cross-Site Scripting (XSS) attacks.

Recommended defensive actions

  • Apply patches or updates provided by BlackBerry to address the vulnerability in UEM 12.23.0 QF8 or earlier
  • Implement additional security measures to detect and prevent Cross-Site Scripting (XSS) attacks
  • Review and update incident response plans to include procedures for handling potential XSS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD details indicate an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, allowing Cross-Site Scripting (XSS). Affected versions include UEM 12.23.0 QF8 or earlier. Limited evidence is available on the exact scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18084 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18084

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18084 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18084

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.