Threat intelligence dashboard
CVE-2026-12351critical

IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection

IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.

Risk score

9.8

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
CWE-74
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 LTSaffectedsemver
10.0.0.0affected

Technical metrics

9.8

CVSS 3.1

Severity
critical
Source
ibm
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H