Skip to content

BlackBerry vulnerabilities

2 CVEs tracked

BlackBerry appears in our reporting primarily in the context of security vulnerabilities within its UEM (Unified Endpoint Management) product. The key incidents are two critical flaws in the UEM Management Console: one allowing arbitrary file download (CVE-2026-18085) and the other enabling a Stored XSS attack (CVE-2026-18084). Both vulnerabilities affect UEM version 12.23.0 QF8 and earlier. Defenders should immediately apply the relevant patches and heed the BlackBerry executive's warning about the critical importance of the first hours in corporate investigations.

Azərbaycanca: BlackBerry, hesabatlarımızda əsasən UEM (Unified Endpoint Management) məhsulu ilə bağlı təhlükəsizlik kontekstində görünür. Əsas hadisə UEM Management Console-da aşkarlanan iki kritik boşluqdur; bunlardan biri özbaşına fayl endirməyə imkan verir (CVE-2026-18085), digəri isə Stored XSS hücumuna səbəb olur (CVE-2026-18084). Hər iki zəiflik UEM 12.23.0 QF8 və daha əvvəlki versiyalara təsir edir. Müdafiəçilər dərhal müvafiq yamaqları tətbiq etməli və şirkət daxili araşdırmalarda ilk saatların kritik əhəmiyyəti barədə BlackBerry rəsmisinin xəbərdarlığını nəzərə almalıdırlar.

This vendor's CVEs2

This hub is built from skopnix's own reporting on BlackBerry: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.