IBM security advisory (AV26-922)
Canadian Cyber Centre relays IBM advisory for Langflow, MQ, and Sterling File Gateway flaws including MQ remote code execution (CVE-2026-13293).
Canadian Cyber Centre advisory AV26-922 relays IBM fixes for Langflow OSS (versions through 1.11.5 across release lines), IBM MQ (10.0.0.0 and 9.x LTS/CD through 9.4.5.1), and Sterling File Gateway (through 6.2.2.1). CVE-2026-13293 is a remote code execution flaw in IBM MQ Java messaging caused by an incomplete security scanner blocklist enabling network-based code execution. CVE-2026-19290 is an improper access control vulnerability in IBM Sterling File Gateway. Administrators are urged to review and apply the necessary updates.
- Langflow OSS, IBM MQ, and Sterling File Gateway affected across listed versions
- CVE-2026-13293: IBM MQ Java messaging RCE via incomplete security scanner blocklist
- CVE-2026-19290: IBM Sterling File Gateway improper access control
- Users and administrators urged to apply IBM updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13293 | Authenticated Remote Code Execution via Deserialization in IBM MQ IBM MQ contains a flaw in which untrusted data is deserialized (CWE-502), allowing a remote authenticated attacker to execute arbitrary code on the system running the queue manager. The flaw is triggered over the network by an attacker holding valid MQ credentials or a compromised application account who submits crafted serialized data that the broker processes, achieving code execution with the privileges of the MQ process. The issue is rated high severity (CVSS 3.1: 8.8) with high impact on confidentiality, integrity, and availability, meaning a successful attacker effectively controls the messaging server and the message traffic it handles. The affected footprint is broad across the supported product line: IBM MQ 9.1 LTS through 9.4 LTS/CD streams and 10.0.0.0. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no exploitation in the wild has been reported, though the authentication requirement makes credential hygiene a critical compensating control. Do: Apply IBM's fix packs and move to builds later than the affected terminal levels (9.1.0.37, 9.2.0.43, 9.3.0.41 / 9.3.5.1, 9.4.0.25 / 9.4.5.1) or off 10.0.0.0 per IBM's security bulletin. Tighten channel authentication with CHLAUTH rules, TLS, and least-privilege MQ user accounts so a single stolen credential cannot reach privileged channels. Review MQ error and authentication logs for unexpected client connections or activity from low-privilege accounts. | 8.8 | — |
| moderate≈ tens of thousands of enterprise installations globally; likely only low thousands of internet-exposed systems (clearly an estimate) | ||
| CVE-2026-19290 | Unauthenticated Information Disclosure in IBM Sterling File Gateway 6.2.x IBM Sterling File Gateway contains an improper access control flaw (CWE-284) that could allow a remote attacker to obtain sensitive information without any authentication or user interaction. The vulnerability affects the 6.2.x release streams from 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1, and is triggered by sending unauthenticated requests to an insufficiently protected interface or resource. An attacker gains read access to sensitive data (high confidentiality impact) but cannot modify data or cause denial of service, per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Organizations using these managed file transfer deployments for B2B data exchange are affected. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof of concept or observed exploitation is known. Do: Apply IBM's fixed builds for the 6.2.0, 6.2.1, and 6.2.2 streams as described in the IBM security bulletin for this CVE. Until patched, restrict network access to Sterling File Gateway interfaces (UI, API, and HTTP-based endpoints) to trusted VPN/internal ranges and enforce authentication at a reverse proxy. Review access logs for unauthenticated requests to sensitive resources from unexpected sources to rule out prior data exposure. | 7.5 | — |
| nichelikely hundreds to low thousands of internet-exposed instances worldwide; total enterprise deployments in the thousands |
Full article159 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-922
Date: September 15, 2026
As of September 14, 2026, IBM is affected by vulnerabilities in the following products:
- Langflow OSS
- Prior to or equal to 1.10.0
- Prior to or equal to 1.10.2
- Prior to or equal to 1.11.2
- Prior to or equal to 1.11.5
- MQ
- 10.0.0.0
- Prior to or equal to 9.1.0.37 LTS
- Prior to or equal to 9.2.0.43 LTS
- Prior to or equal to 9.3.0.41 LTS
- Prior to or equal to 9.3.5.1 CD
- Prior to or equal to 9.4.0.25 LTS
- Prior to or equal to 9.4.5.1 CD
- Sterling File Gateway
- Prior to or equal to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1
The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-922