<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Control-M (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/controlm.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/controlm-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Control-M (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-23781 – An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of def...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23781</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23781</strong></p>
  <p>An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23782 – An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23782</guid>
    <pubDate>Fri, 10 Apr 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23782</strong></p>
  <p>An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23780 – An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23780</guid>
    <pubDate>Fri, 10 Apr 2026 15:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23780</strong></p>
  <p>An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55108 – The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55108</guid>
    <pubDate>Wed, 05 Nov 2025 09:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55108</strong></p>
  <p>The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration).   NOTE:     *  The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use s…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55118 – Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55118</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55118</strong></p>
  <p>Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.   The issue occurs in the following cases:    *  Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n";   *  Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55116 – A buffer overflow in the Control-M/Agent can lead to a local privilege escalatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55116</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55116</strong></p>
  <p>A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent.  This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55115 – A path traversal in the Control-M/Agent can lead to a local privilege escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55115</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55115</strong></p>
  <p>A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100 and above.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55113 – If the Access Control List is enforced by the Control-M/Agent and the C router i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55113</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55113</strong></p>
  <p>If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-158</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55112 – Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55112</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55112</strong></p>
  <p>Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55109 – An authentication bypass vulnerability exists in the out-of-support Control-M/Ag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55109</guid>
    <pubDate>Tue, 16 Sep 2025 13:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55109</strong></p>
  <p>An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client authentication can bypass the need for a certificate signed by the certificate autho…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39122 – BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39122</guid>
    <pubDate>Mon, 31 Jul 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39122</strong></p>
  <p>BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26550 – A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26550</guid>
    <pubDate>Sat, 25 Feb 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26550</strong></p>
  <p>A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19220 – BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19220</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19220</strong></p>
  <p>BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19219 – BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19219</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19219</strong></p>
  <p>BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19218 – BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19218</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19218</strong></p>
  <p>BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19217 – BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19217</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19217</strong></p>
  <p>BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19216 – BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19216</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19216</strong></p>
  <p>BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19215 – A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19215</guid>
    <pubDate>Thu, 30 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19215</strong></p>
  <p>A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10238 – In QSEE in all Android releases from CAF using the Linux kernel access control m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10238</guid>
    <pubDate>Tue, 16 May 2017 14:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10238</strong></p>
  <p>In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10238">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
