Threat intelligence dashboard
CVE-2026-11729high

IBM MQ Java messaging is vulnerable to remote code execution

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.

Risk score

8.5

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
CWE-502
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.1.0.0 to 9.1.0.37 LTSaffectedsemver
9.2.0.0 to 9.2.0.43 LTSaffectedsemver
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 CDaffectedsemver
10.0.0.0affected

Technical metrics

8.5

CVSS 3.1

Severity
high
Source
ibm
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H