Threat intelligence dashboard
CVE-2026-12728high

IBM MQ Java messaging is vulnerable to remote code execution

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.

Risk score

8.8

CVSS 3.1

Vendor
IBM
Product
MQ
CWE
Not available
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

MQ

IBM

Version / rangeStatusType
9.1.0.0 to 9.1.0.37 LTSaffectedsemver
9.2.0.0 to 9.2.0.43 LTSaffectedsemver
9.3.0.0 to 9.3.0.41 LTSaffectedsemver
9.3.0.0 to 9.3.5.1 CDaffectedsemver
9.4.0.0 to 9.4.0.25 LTSaffectedsemver
9.4.0.0 to 9.4.5.1 CDaffectedsemver
10.0.0.0affected

Technical metrics

8.8

CVSS 3.1

Severity
high
Source
ibm
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H