Threat intelligence dashboard
CVE-2026-12355high

IBM MQ Resource Adapter IVT servlet is vulnerable to unauthenticated remote code execution

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.

Risk score

8.1

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
CWE-74
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.1.0.0 to 9.1.0.37 LTSaffectedsemver
9.2.0.0 to 9.2.0.43 LTSaffectedsemver
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 CDaffectedsemver
10.0.0.0affected

Technical metrics

8.1

CVSS 3.1

Severity
high
Source
ibm
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H