ZeroHour

CVE-2026-12728

moderate

Authenticated RCE via Unsafe Deserialization in IBM MQ

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM MQ contains a deserialization-of-untrusted-data flaw that allows an authenticated, remote attacker to execute arbitrary code on the affected queue manager. Exploitation requires valid credentials to the MQ service, after which the attacker sends crafted serialized data that is deserialized insecurely, yielding code execution with the privileges of the MQ process. Successful exploitation compromises confidentiality, integrity, and availability of the messaging backbone, which typically carries sensitive transactional data in banking, retail, and government environments. All currently supported IBM MQ streams are affected, spanning the 9.1 through 9.4 LTS and CD streams as well as 10.0.0.0. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not currently known.

What to do: Apply the fix packs IBM released for this advisory on every affected LTS and CD stream (i.e., versions later than the affected ranges listed above, per IBM's security bulletin) and prioritize 10.0.0.0 instances. Restrict administrative and application credentials, since exploitation requires authentication: enforce least-privilege MQ authorities, segment queue manager listeners and web consoles from untrusted networks, and disable or firewall-exposure-limit the MQ console where feasible. Review authentication and channel activity logs for anomalous behavior by low-privilege accounts preceding any unexpected process execution on MQ hosts.

Affected
IBM MQ9.1.0.0 through 9.1.0.37 LTS
IBM MQ9.2.0.0 through 9.2.0.43 LTS
IBM MQ9.3.0.0 through 9.3.0.41 LTS
IBM MQ9.3.0.0 through 9.3.5.1 CD
IBM MQ9.4.0.0 through 9.4.0.25 LTS
IBM MQ9.4.0.0 through 9.4.5.1 CD
IBM MQ10.0.0.0
Estimated exposure
moderate≈ a few thousand internet-exposed IBM MQ queue managers/consoles (order 1k–10k), plus a much larger internal enterprise installed base — Public internet scan engines (Shodan/Censys) typically show low-thousands of hosts exposing IBM MQ listener (1414) and web console (9443/9729) ports, while IBM MQ's overall deployment base spans thousands of large enterprises but sits…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.