BMC Control-M deployments are affected by two newly disclosed vulnerabilities that expose Control-M/Server and related components to serious remote attacks. CVE-2026-10539 is a critical unauthenticated command injection flaw in Control-M/Server communication commands that can let a remote attacker execute unauthorized commands and potentially fully compromise a server. The issue affects Control-M/Server versions 9.0.20.x through 9.0.21.200, and possibly earlier unsupported releases, and is rated CVSS 4.0 9.5 / CVSS 3.1 9.0.
A second issue, CVE-2026-10538, is a high-severity improper deserialization vulnerability in out-of-support Control-M/Server and Control-M/Enterprise Manager 9.0.20.x components, particularly in messaging consumer functionality that processes user-controlled serialized data. An authenticated attacker could remotely trigger unintended server-side behavior through crafted serialized content; the flaw is rated CVSS 4.0 8.9 / CVSS 3.1 8.0. Organizations running affected Control-M versions have been advised to upgrade to supported releases, apply vendor patches, harden deserialization controls, restrict access to exposed services, and monitor for suspicious command execution or messaging activity.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A critical unauthenticated command injection vulnerability in Control-M/Server communication commands was published as CVE-2026-10539. The flaw affects Control-M/Server versions 9.0.20.x through 9.0.21.200 inclusive and could allow remote attackers to execute unauthorized commands on affected servers.
A high-severity improper deserialization vulnerability affecting out-of-support BMC Control-M/Server and Control-M/Enterprise Manager 9.0.20.x and potentially earlier versions was published as CVE-2026-10538. The issue allows an authenticated remote attacker to trigger unintended server-side behavior via crafted serialized content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
my.f5.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.