Multiple Vulnerabilities in IBM MQ
IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.
CVE search metadata
CVE search record: CVE-2024-49033. Severity: high. CVSS: 7.5. EPSS: 2.10%. KEV: no. Product: MQ. Brief: Multiple Vulnerabilities in IBM MQ. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/
CVE search record: CVE-2024-49035. Severity: high. CVSS: 8.7. EPSS: 1.30%. KEV: no. Product: MQ. Brief: Multiple Vulnerabilities in IBM MQ. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/
IBM has disclosed multiple security vulnerabilities affecting the IBM MQ messaging software. These flaws, tracked as CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, present significant risks to systems running the software. Successful exploitation of these vulnerabilities may allow an unauthenticated or authenticated attacker to achieve arbitrary remote code execution (RCE) on the underlying host, trigger a Denial of Service (DoS) condition, gain access to sensitive information, or perform unauthorized data manipulation. Defenders should prioritize patching and configuration reviews for all instances of IBM MQ, as these vulnerabilities impact the integrity and availability of messaging infrastructure, which often serves as a critical backbone for enterprise applications.
Impact
Successful exploitation could result in the total compromise of the host system, loss of message confidentiality, and disruption of critical business services that rely on IBM MQ for communication. These vulnerabilities affect all deployments of the software, and organizations should apply vendor-provided security updates to mitigate these risks.
Recommendation
- Identify all IBM MQ deployments across the environment using asset inventory systems.
- Review the IBM security advisory for the specific fixed versions associated with CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035.
- Apply the latest security patches provided by IBM to all MQ instances.
- Implement network segmentation to limit access to MQ listener ports (typically 1414) to authorized clients only to reduce the attack surface.
Immediate actions
Patch IBM MQ instances to the versions identified in the IBM security bulletin
Mitigations
Restrict network access to IBM MQ listeners
CVE-2024-49033, CVE-2024-49034, CVE-2024-49035