Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

IBM MQ versions 9.1 through 10.0 expose an authenticated attacker to arbitrary code execution by deserializing untrusted data. This is an insecure deserialization flaw, identified as CWE-502. The vulnerability allows a privileged user to inject malicious payloads that are processed by the MQ server, enabling the attacker to run arbitrary code with the privileges of the MQ process. This can lead to full system compromise and significant confidentiality, integrity, and availability impacts. The CVSS score of 8.8 attests to its high severity.

Affected Systems

IBM MQ is affected. Impacted releases include IBM MQ 9.1 LTS from build 9.1.0.0 through 9.1.0.37, 9.2 LTS from 9.2.0.0 through 9.2.0.43, 9.3 LTS from 9.3.0.0 through 9.3.0.41 and 9.3.5.1 CD, 9.4 LTS from 9.4.0.0 through 9.4.0.25 and 9.4.5.1 CD, and IBM MQ 10.0.0.0. The advisory lists specific cumulative security updates for each version that contain the fix.

Risk and Exploitability

It is not listed in the CISA KEV catalog, but its EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The high CVSS score signals a strong potential attack. Because authentication is required, the risk primarily applies to environments where valid credentials or compromised accounts exist. Based on the description, the likely attack vector is a remote client connection that sends crafted serialized objects to the MQ server over the standard MQ client protocol, requiring authenticated credentials. Exploitation would need an attacker to send these crafted objects, which is feasible over a remote connection. Given the severity, security teams should consider the exposure high until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 16:09 UTC.

Remediation

Vendor Solution

This issue was addressed under Known Issue DT474370 IBM MQ version 9.1 LTS Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts IBM MQ version 9.2 LTS Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts IBM MQ version 9.3 LTS Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts IBM MQ version 9.4 LTS Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0 Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100


OpenCVE Recommended Actions

  • Apply the latest cumulative security update for your IBM MQ version: 9.1.0.38 for MQ 9.1, 9.2.0.44 for MQ 9.2, 9.3.0.42 for MQ 9.3, 9.4.0.26 for MQ 9.4, and upgrade to 10.0.0.5 for MQ 10.0.0.0, 9.3 CD, and 9.4 CD versions.
  • Ensure that only trusted clients can connect to the MQ broker by implementing strong authentication and limiting network exposure to the MQ ports.
  • Audit MQ server logs for unusual deserialization activity and monitor for any unexpected command execution attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
Title IBM MQ Java messaging is vulnerable to remote code execution
First Time appeared Ibm
Ibm mq
CPEs cpe:2.3:a:ibm:mq:10.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.43:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.4.5.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm mq
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T14:58:00.272Z

Reserved: 2026-06-19T15:24:53.564Z

Link: CVE-2026-12728

cve-icon Vulnrichment

Updated: 2026-09-15T19:02:35.726Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:14.547

Modified: 2026-09-17T15:16:40.963

Link: CVE-2026-12728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data