


Perceptive Security
SOC/SIEM Consultancy

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthe…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 09:01:54
Source:
nvd.nist.gov
Enterprise Applications, Zero-Day Vulnerabilities
A vulnerability in BMC Control-M/Server allows unauthenticated attackers to execute unauthorized commands due to insufficient input filtering or sanitization in a communication command. The flaw exists in versions 9.0.20.x through 9.0.21.200 and potentially earlier unsupported versions. Successful exploitation could lead to full server compromise. No authentication is required to exploit this vulnerability, significantly raising its severity. The vulnerability was published via NVD and BMC has issued a knowledge article with remediation guidance.
Technical details
Mitigation steps:
Affected products:
BMC Control-M/Server 9.0.20.x
BMC Control-M/Server 9.0.21.200
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10539
https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=kA3cx000000GFZNCA4&type=Solution
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
