IBM MQ Java messaging is vulnerable to remote code execution
Published Sep 14, 2026
8.8
HIGHCVSS 3.1
EPSS 0.65%
Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Affected products
-
- Version 10.0.0.0StatusaffectedConstraints-
- Version 9.1.0.0StatusaffectedConstraints<=9.1.0.37 LTS
- Version 9.2.0.0StatusaffectedConstraints<=9.2.0.43 LTS
- Version 9.3.0.0StatusaffectedConstraints<=9.3.0.41 LTS
- Version 9.3.0.0StatusaffectedConstraints<=9.3.5.1 CD
- Version 9.4.0.0StatusaffectedConstraints<=9.4.0.25 LTS
- Version 9.4.0.0StatusaffectedConstraints<=9.4.5.1 CD
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue was addressed under Known Issue DT474598
IBM MQ version 9.1 LTS
Apply cumulative security update 9.1.0.38 https://www.ibm.com/support/pages/downloading-ibm-mq-91-lts
IBM MQ version 9.2 LTS
Apply cumulative security update 9.2.0.44 https://www.ibm.com/support/pages/downloading-ibm-mq-92-lts
IBM MQ version 9.3 LTS
Apply cumulative security update 9.3.0.42 https://www.ibm.com/support/pages/downloading-ibm-mq-93-lts
IBM MQ version 9.4 LTS
Apply cumulative security update https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts 9.4.0.26 https://www.ibm.com/support/pages/downloading-ibm-mq-94-lts
IBM MQ version 9.3 CD, 9.4 CD and 10.0.0.0
Upgrade to IBM MQ version 10.0.0.5 https://www.ibm.com/support/pages/downloading-ibm-mq-100
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78152 Advisory
- https://www.ibm.com/support/pages/node/7284896 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78152 | Advisory | |
| https://www.ibm.com/support/pages/node/7284896 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.