BlackBerry UEM Management Console is affected by CVE-2026-18084, a high-severity cross-site scripting flaw caused by improper neutralization of the time zone parameter during web page generation. The vulnerability impacts BlackBerry UEM 12.23.0 QF8 and earlier, with affected release history also including 12.22.1 QF7 and earlier; advisories describe systems prior to QF9 as vulnerable. An unauthenticated remote attacker can inject malicious JavaScript that executes when an authenticated administrator loads the affected page.
Successful exploitation can lead to session token theft, full takeover of the UEM console, unauthorized policy changes, exposure of sensitive corporate data, malicious configuration changes on enrolled devices, and potential lateral movement into the broader enterprise network. BlackBerry has advised customers to upgrade to QF9 or later immediately, while defenders are also being urged to restrict management console access, enforce MFA, and monitor logs for anomalous activity that could indicate exploitation attempts.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
BlackBerry published an advisory for CVE-2026-18084, a CWE-79 cross-site scripting flaw in the BlackBerry UEM Management Console involving the time zone parameter. The issue affects BlackBerry UEM 12.23.0 QF8 or earlier, with remediation guidance pointing customers to QF9 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.