Back

HIGH

IBM MQ Java messaging is vulnerable to remote code execution

Published Sep 14, 2026

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

Affected products

Remediation

Vendor solution

This issue was addressed under Known Issue DT474598

IBM MQ version 9.1 LTS

Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts

IBM MQ version 9.2 LTS

Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts

IBM MQ version 9.3 LTS

Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts

IBM MQ version 9.4 LTS

Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts  9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts

IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0

Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 14, 2026
Updated Sep 16, 2026
Reserved Jun 24, 2026
CISA Vulnrichment
Updated Sep 15, 2026
NVD
Status Awaiting Analysis
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Sep 14, 2026
Updated Sep 16, 2026
Exploited since n/a
EUVD-2026-78152