Junglewise Threat Intelligence

CVE-2026-12728: IBM MQ deserialization bypass remote code execution

CVE-2026-12728 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

IBM MQ is a message queuing system used to reliably transmit messages between applications in enterprise environments. A flaw in the Java client's deserialization handling allows authenticated attackers to bypass security filters and execute arbitrary code by sending specially crafted messages, potentially compromising the entire messaging infrastructure and any connected systems.

Technical details

This is a deserialization filter bypass vulnerability in IBM MQ's Java messaging component. The vulnerability exists in the distributed messaging component where the deserialization allowlist can be bypassed by an authenticated attacker sending crafted serialized messages. The attack requires network access to the MQ infrastructure and valid authentication credentials. Successful exploitation allows remote code execution with the privileges of the MQ process. IBM has released patches for all affected versions, with versions 9.1 through 9.4 LTS requiring cumulative security updates and 10.0.0.0 requiring an upgrade to 10.0.0.5.

Affected products

  • IBM MQ 9.1.0.0 to 9.1.0.37 LTS, 9.2.0.0 to 9.2.0.43 LTS, 9.3.0.0 to 9.3.0.41 LTS, 9.3.0.0 to 9.3.5.1 CD, 9.4.0.0 to 9.4.0.25 LTS, 9.4.0.0 to 9.4.5.1 CD, 10.0.0.0

Timeline

  • 2026-09-14: disclosed: IBM security bulletin published
  • 2026-09-14: patched: Patches available: MQ 9.1.0.38, 9.2.0.44, 9.3.0.42, 9.4.0.26 LTS, and 10.0.0.5

References

Related threats