<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:microsoft:partner_center:-:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftpartner_center-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 13:04:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftpartner_center-/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in IBM MQ</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/</link><pubDate>Tue, 15 Sep 2026 13:04:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-mq-vulnerabilities/</guid><description>IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.</description><content:encoded><![CDATA[<p>IBM has disclosed multiple security vulnerabilities affecting the IBM MQ messaging software. These flaws, tracked as CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, present significant risks to systems running the software. Successful exploitation of these vulnerabilities may allow an unauthenticated or authenticated attacker to achieve arbitrary remote code execution (RCE) on the underlying host, trigger a Denial of Service (DoS) condition, gain access to sensitive information, or perform unauthorized data manipulation. Defenders should prioritize patching and configuration reviews for all instances of IBM MQ, as these vulnerabilities impact the integrity and availability of messaging infrastructure, which often serves as a critical backbone for enterprise applications.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could result in the total compromise of the host system, loss of message confidentiality, and disruption of critical business services that rely on IBM MQ for communication. These vulnerabilities affect all deployments of the software, and organizations should apply vendor-provided security updates to mitigate these risks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all IBM MQ deployments across the environment using asset inventory systems.</li>
<li>Review the IBM security advisory for the specific fixed versions associated with CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035.</li>
<li>Apply the latest security patches provided by IBM to all MQ instances.</li>
<li>Implement network segmentation to limit access to MQ listener ports (typically 1414) to authorized clients only to reduce the attack surface.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>messaging-middleware</category><category>remote-code-execution</category></item></channel></rss>