{"schema_version":1,"title":"IBM Mq vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in IBM Mq: 0 in the last 7 days and 22 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-11725, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/mq","json_url":"https://junglewise.ai/threats/technologies/mq.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mq","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":20,"all_time":22,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":22,"last_90_days":22,"last_365_days":22},"latest":[{"cve":"CVE-2026-11725","cvss":8.8,"epss":0.0041,"slug":"cve-2026-11725-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ integer overflow in MQINQ request","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:03.167+00:00","url":"https://junglewise.ai/threats/cve-2026-11725-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-11378","cvss":8.8,"epss":0.0034,"slug":"cve-2026-11378-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ integer overflow in distribution list processing","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:05.62+00:00","url":"https://junglewise.ai/threats/cve-2026-11378-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-11375","cvss":8.8,"epss":0.0035,"slug":"cve-2026-11375-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ stack buffer overflow in XA transaction handling","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:05.47+00:00","url":"https://junglewise.ai/threats/cve-2026-11375-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-10853","cvss":7.5,"epss":0.0037,"slug":"cve-2026-10853-ibm-mq-could-allow-an-authenticated-attacker-with-cluster-access","title":"IBM MQ heap buffer overflow in cluster repository manager","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:05.167+00:00","url":"https://junglewise.ai/threats/cve-2026-10853-ibm-mq-could-allow-an-authenticated-attacker-with-cluster-access"},{"cve":"CVE-2026-10751","cvss":7.5,"epss":0.0037,"slug":"cve-2026-10751-ibm-mq-java-and-jms-client-libraries-deserialization-bypass","title":"IBM MQ Java and JMS client libraries deserialization bypass","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:04.563+00:00","url":"https://junglewise.ai/threats/cve-2026-10751-ibm-mq-java-and-jms-client-libraries-deserialization-bypass"},{"cve":"CVE-2026-10575","cvss":8.8,"epss":0.0028,"slug":"cve-2026-10575-ibm-mq-heap-buffer-overflow-in-mqput-operations","title":"IBM MQ heap buffer overflow in MQPUT operations","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:04.15+00:00","url":"https://junglewise.ai/threats/cve-2026-10575-ibm-mq-heap-buffer-overflow-in-mqput-operations"},{"cve":"CVE-2026-10030","cvss":7.1,"epss":0.0023,"slug":"cve-2026-10030-ibm-mq-console-privilege-escalation-in-authorization-checks","title":"IBM MQ Console privilege escalation in authorization checks","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:04.02+00:00","url":"https://junglewise.ai/threats/cve-2026-10030-ibm-mq-console-privilege-escalation-in-authorization-checks"},{"cve":"CVE-2026-10027","cvss":8.1,"epss":0.0038,"slug":"cve-2026-10027-ibm-mq-buffer-overflow-in-message-decompression","title":"IBM MQ buffer overflow in message decompression","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:03.873+00:00","url":"https://junglewise.ai/threats/cve-2026-10027-ibm-mq-buffer-overflow-in-message-decompression"},{"cve":"CVE-2026-12728","cvss":8.8,"epss":0.0036,"slug":"cve-2026-12728-ibm-mq-deserialization-bypass-remote-code-execution","title":"IBM MQ deserialization bypass remote code execution","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:14.547+00:00","url":"https://junglewise.ai/threats/cve-2026-12728-ibm-mq-deserialization-bypass-remote-code-execution"},{"cve":"CVE-2026-12667","cvss":7.1,"epss":0.0027,"slug":"cve-2026-12667-ibm-mq-xxe-injection-in-net-client-rfh2-parser","title":"IBM MQ XXE injection in .NET client RFH2 parser","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:14.42+00:00","url":"https://junglewise.ai/threats/cve-2026-12667-ibm-mq-xxe-injection-in-net-client-rfh2-parser"},{"cve":"CVE-2026-12666","cvss":8.1,"epss":0.0026,"slug":"cve-2026-12666-ibm-mq-xml-external-entity-injection-in-mqrfh2-header","title":"IBM MQ XML external entity injection in MQRFH2 header","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:14.29+00:00","url":"https://junglewise.ai/threats/cve-2026-12666-ibm-mq-xml-external-entity-injection-in-mqrfh2-header"},{"cve":"CVE-2026-12355","cvss":8.1,"epss":0.0038,"slug":"cve-2026-12355-ibm-mq-jndi-injection-in-resource-adapter-ivt-servlet","title":"IBM MQ JNDI injection in Resource Adapter IVT servlet","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:13.98+00:00","url":"https://junglewise.ai/threats/cve-2026-12355-ibm-mq-jndi-injection-in-resource-adapter-ivt-servlet"},{"cve":"CVE-2026-12354","cvss":7.5,"epss":0.0033,"slug":"cve-2026-12354-ibm-mq-jndi-injection-in-resource-adapter-ivt","title":"IBM MQ JNDI injection in Resource Adapter IVT","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:13.847+00:00","url":"https://junglewise.ai/threats/cve-2026-12354-ibm-mq-jndi-injection-in-resource-adapter-ivt"},{"cve":"CVE-2026-12351","cvss":9.8,"epss":0.0048,"slug":"cve-2026-12351-ibm-mq-remote-code-execution-via-jndi-injection","title":"IBM MQ remote code execution via JNDI injection","severity":"critical","exploited":false,"published_at":"2026-09-15T18:17:13.727+00:00","url":"https://junglewise.ai/threats/cve-2026-12351-ibm-mq-remote-code-execution-via-jndi-injection"},{"cve":"CVE-2026-12150","cvss":7,"epss":0.0017,"slug":"cve-2026-12150-ibm-mq-stack-based-buffer-overflow-in-tls-certificate-parser","title":"IBM MQ stack-based buffer overflow in TLS certificate parser","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:13.597+00:00","url":"https://junglewise.ai/threats/cve-2026-12150-ibm-mq-stack-based-buffer-overflow-in-tls-certificate-parser"},{"cve":"CVE-2026-11729","cvss":8.5,"epss":0.0029,"slug":"cve-2026-11729-ibm-mq-unsafe-deserialization-in-java-client","title":"IBM MQ unsafe deserialization in Java client","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:12.393+00:00","url":"https://junglewise.ai/threats/cve-2026-11729-ibm-mq-unsafe-deserialization-in-java-client"},{"cve":"CVE-2026-11728","cvss":8.1,"epss":0.0035,"slug":"cve-2026-11728-ibm-mq-net-client-heap-buffer-overflow","title":"IBM MQ .NET client heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:12.257+00:00","url":"https://junglewise.ai/threats/cve-2026-11728-ibm-mq-net-client-heap-buffer-overflow"},{"cve":"CVE-2026-13265","cvss":6.8,"epss":0.0022,"slug":"cve-2026-13265-ibm-mq-xml-external-entity-injection-in-managed-file-transfer","title":"IBM MQ XML external entity injection in Managed File Transfer","severity":"medium","exploited":false,"published_at":"2026-09-14T22:16:57.1+00:00","url":"https://junglewise.ai/threats/cve-2026-13265-ibm-mq-xml-external-entity-injection-in-managed-file-transfer"},{"cve":"CVE-2026-13293","cvss":8.8,"epss":0.006,"slug":"cve-2026-13293-ibm-mq-java-deserialization-remote-code-execution","title":"IBM MQ Java deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:02.13+00:00","url":"https://junglewise.ai/threats/cve-2026-13293-ibm-mq-java-deserialization-remote-code-execution"},{"cve":"CVE-2026-13287","cvss":7.1,"epss":0.0039,"slug":"cve-2026-13287-ibm-mq-xml-external-entity-injection-in-managed-file-transfer","title":"IBM MQ XML external entity injection in Managed File Transfer","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:01.977+00:00","url":"https://junglewise.ai/threats/cve-2026-13287-ibm-mq-xml-external-entity-injection-in-managed-file-transfer"},{"cve":"CVE-2026-13285","cvss":7.1,"epss":0.0039,"slug":"cve-2026-13285-ibm-mq-xml-external-entity-injection-in-managed-file-transfer","title":"IBM MQ XML external entity injection in Managed File Transfer","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:01.823+00:00","url":"https://junglewise.ai/threats/cve-2026-13285-ibm-mq-xml-external-entity-injection-in-managed-file-transfer"},{"cve":"CVE-2026-13275","cvss":7.1,"epss":0.0025,"slug":"cve-2026-13275-ibm-mq-managed-file-transfer-xml-external-entity-injection","title":"IBM MQ Managed File Transfer XML external entity injection","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:01.393+00:00","url":"https://junglewise.ai/threats/cve-2026-13275-ibm-mq-managed-file-transfer-xml-external-entity-injection"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":22},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM App Connect Enterprise","slug":"app-connect-enterprise","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/app-connect-enterprise"},{"name":"IBM Db2","slug":"db2","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/db2"},{"name":"IBM Verify Identity Access","slug":"verify-identity-access","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/verify-identity-access"},{"name":"IBM Power Systems Firmware","slug":"power-systems-firmware","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/power-systems-firmware"}],"technology":{"hub":true,"name":"IBM Mq","slug":"mq","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"service","url":"https://junglewise.ai/threats/technologies/mq"},"most_severe":[{"cve":"CVE-2026-12351","cvss":9.8,"epss":0.0048,"slug":"cve-2026-12351-ibm-mq-remote-code-execution-via-jndi-injection","title":"IBM MQ remote code execution via JNDI injection","severity":"critical","exploited":false,"published_at":"2026-09-15T18:17:13.727+00:00","url":"https://junglewise.ai/threats/cve-2026-12351-ibm-mq-remote-code-execution-via-jndi-injection"},{"cve":"CVE-2026-13293","cvss":8.8,"epss":0.006,"slug":"cve-2026-13293-ibm-mq-java-deserialization-remote-code-execution","title":"IBM MQ Java deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:02.13+00:00","url":"https://junglewise.ai/threats/cve-2026-13293-ibm-mq-java-deserialization-remote-code-execution"},{"cve":"CVE-2026-11725","cvss":8.8,"epss":0.0041,"slug":"cve-2026-11725-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ integer overflow in MQINQ request","severity":"high","exploited":false,"published_at":"2026-09-18T20:17:03.167+00:00","url":"https://junglewise.ai/threats/cve-2026-11725-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-12728","cvss":8.8,"epss":0.0036,"slug":"cve-2026-12728-ibm-mq-deserialization-bypass-remote-code-execution","title":"IBM MQ deserialization bypass remote code execution","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:14.547+00:00","url":"https://junglewise.ai/threats/cve-2026-12728-ibm-mq-deserialization-bypass-remote-code-execution"},{"cve":"CVE-2026-11375","cvss":8.8,"epss":0.0035,"slug":"cve-2026-11375-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ stack buffer overflow in XA transaction handling","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:05.47+00:00","url":"https://junglewise.ai/threats/cve-2026-11375-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-11378","cvss":8.8,"epss":0.0034,"slug":"cve-2026-11378-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of","title":"IBM MQ integer overflow in distribution list processing","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:05.62+00:00","url":"https://junglewise.ai/threats/cve-2026-11378-ibm-mq-could-allow-an-authenticated-attacker-to-cause-a-denial-of"},{"cve":"CVE-2026-10575","cvss":8.8,"epss":0.0028,"slug":"cve-2026-10575-ibm-mq-heap-buffer-overflow-in-mqput-operations","title":"IBM MQ heap buffer overflow in MQPUT operations","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:04.15+00:00","url":"https://junglewise.ai/threats/cve-2026-10575-ibm-mq-heap-buffer-overflow-in-mqput-operations"},{"cve":"CVE-2026-11729","cvss":8.5,"epss":0.0029,"slug":"cve-2026-11729-ibm-mq-unsafe-deserialization-in-java-client","title":"IBM MQ unsafe deserialization in Java client","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:12.393+00:00","url":"https://junglewise.ai/threats/cve-2026-11729-ibm-mq-unsafe-deserialization-in-java-client"},{"cve":"CVE-2026-10027","cvss":8.1,"epss":0.0038,"slug":"cve-2026-10027-ibm-mq-buffer-overflow-in-message-decompression","title":"IBM MQ buffer overflow in message decompression","severity":"high","exploited":false,"published_at":"2026-09-18T16:17:03.873+00:00","url":"https://junglewise.ai/threats/cve-2026-10027-ibm-mq-buffer-overflow-in-message-decompression"},{"cve":"CVE-2026-12355","cvss":8.1,"epss":0.0038,"slug":"cve-2026-12355-ibm-mq-jndi-injection-in-resource-adapter-ivt-servlet","title":"IBM MQ JNDI injection in Resource Adapter IVT servlet","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:13.98+00:00","url":"https://junglewise.ai/threats/cve-2026-12355-ibm-mq-jndi-injection-in-resource-adapter-ivt-servlet"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}