Skip to content
Threat Feed

CPE

Cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*:*

8 briefs RSS
high advisory

Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)

An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability remote-code-execution ibm-mq
1c
high advisory

IBM MQ Improper Validation Vulnerability (CVE-2026-11381)

IBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability cve middleware
1c
high threat

Stack Buffer Overflow in IBM MQ XA Transaction Processing

IBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.

exploited MQ vulnerability remote-code-execution denial-of-service
1c
high advisory

Vulnerability in IBM MQ Cluster Command Message Validation

IBM MQ contains a vulnerability (CVE-2026-10853) where improper cluster command message length validation allows authenticated attackers to cause a denial of service or remote code execution.

MQ
1c
high advisory

IBM MQ Java and JMS Client Deserialization Vulnerability

An authenticated attacker can execute arbitrary code on client applications by exploiting a deserialization filter bypass in IBM MQ Java and JMS client libraries.

IBM MQ
1t 1c
high advisory

Buffer Overflow Vulnerability in IBM MQ

IBM MQ is vulnerable to a buffer overflow during the processing of malformed compressed data, which can be leveraged by a remote attacker for denial of service or arbitrary code execution.

MQ
2t 1c
high advisory

XML External Entity Injection in IBM MQ Classes for Java

An XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.

IBM MQ +1 vulnerability java middleware cve-2026-12666 rce dos
1t 1c updated
high advisory

IBM MQ XML External Entity Injection Vulnerability

An XML external entity injection vulnerability in IBM MQ allows authenticated attackers to perform arbitrary file reads or server-side request forgery during reply message processing.

MQ
1t 1c