CVE-2026-12728
moderateAuthenticated RCE via Unsafe Deserialization in IBM MQ
IBM MQ contains a deserialization-of-untrusted-data flaw that allows an authenticated, remote attacker to execute arbitrary code on the affected queue manager. Exploitation requires valid credentials to the MQ service, after which the attacker sends crafted serialized data that is deserialized insecurely, yielding code execution with the privileges of the MQ process. Successful exploitation compromises confidentiality, integrity, and availability of the messaging backbone, which typically carries sensitive transactional data in banking, retail, and government environments. All currently supported IBM MQ streams are affected, spanning the 9.1 through 9.4 LTS and CD streams as well as 10.0.0.0. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not currently known.
What to do: Apply the fix packs IBM released for this advisory on every affected LTS and CD stream (i.e., versions later than the affected ranges listed above, per IBM's security bulletin) and prioritize 10.0.0.0 instances. Restrict administrative and application credentials, since exploitation requires authentication: enforce least-privilege MQ authorities, segment queue manager listeners and web consoles from untrusted networks, and disable or firewall-exposure-limit the MQ console where feasible. Review authentication and channel activity logs for anomalous behavior by low-privilege accounts preceding any unexpected process execution on MQ hosts.
| IBM MQ | 9.1.0.0 through 9.1.0.37 LTS |
| IBM MQ | 9.2.0.0 through 9.2.0.43 LTS |
| IBM MQ | 9.3.0.0 through 9.3.0.41 LTS |
| IBM MQ | 9.3.0.0 through 9.3.5.1 CD |
| IBM MQ | 9.4.0.0 through 9.4.0.25 LTS |
| IBM MQ | 9.4.0.0 through 9.4.5.1 CD |
| IBM MQ | 10.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.