<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IBM MQ (9.1.0.0 Through 9.1.0.37 LTS, 9.2.0.0 Through 9.2.0.43 LTS, 9.3.0.0 Through 9.3.0.41 LTS, 9.3.0.0 Through 9.3.5.1 CD, 9.4.0.0 Through 9.4.0.25 LTS, 9.4.0.0 Through 9.4.5.1 CD, and 10.0.0.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ibm-mq-9.1.0.0-through-9.1.0.37-lts-9.2.0.0-through-9.2.0.43-lts-9.3.0.0-through-9.3.0.41-lts-9.3.0.0-through-9.3.5.1-cd-9.4.0.0-through-9.4.0.25-lts-9.4.0.0-through-9.4.5.1-cd-and-10.0.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 19:42:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ibm-mq-9.1.0.0-through-9.1.0.37-lts-9.2.0.0-through-9.2.0.43-lts-9.3.0.0-through-9.3.0.41-lts-9.3.0.0-through-9.3.5.1-cd-9.4.0.0-through-9.4.0.25-lts-9.4.0.0-through-9.4.5.1-cd-and-10.0.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>XML External Entity Injection in IBM MQ Classes for Java</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-12666/</link><pubDate>Tue, 15 Sep 2026 19:42:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-12666/</guid><description>An XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.</description><content:encoded><![CDATA[<p>IBM MQ Classes for Java is susceptible to an XML external entity (XXE) injection vulnerability, identified as CVE-2026-12666. This flaw exists within the processing logic of the MQRFH2 header, which is utilized for message metadata in IBM MQ environments. By submitting specially crafted MQRFH2 headers containing malicious XML external entities, an authenticated attacker can force the application to process unauthorized file inclusions or external URI requests. Successful exploitation enables the attacker to read sensitive files from the underlying host filesystem or trigger resource exhaustion, resulting in a denial-of-service (DoS) condition. This vulnerability affects a wide range of IBM MQ LTS and CD releases across various versions including 9.1, 9.2, 9.3, 9.4, and 10.0. Given the high CVSS base score of 8.1, organizations running these versions of IBM MQ Classes for Java should prioritize patching as recommended by IBM.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to the integrity and availability of IBM MQ deployments. If successfully exploited, attackers can potentially exfiltrate configuration files, system credentials, or other sensitive data accessible to the user context running the Java process. Furthermore, the capacity to induce a denial-of-service attack can disrupt critical messaging middleware services, impacting downstream applications that rely on IBM MQ for data transmission and integration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update IBM MQ Classes for Java to the latest patched version as specified in the official IBM security bulletin to remediate CVE-2026-12666.</li>
<li>Audit IBM MQ queue manager configurations to restrict the use of unauthenticated or unauthorized applications that can inject messages into protected queues, as exploitation requires an authenticated session.</li>
<li>Review existing Java application logs for anomalies in MQRFH2 header processing or unusual file access patterns originating from the JVM process.</li>
<li>Since this is a library-level vulnerability, coordinate with application development teams to identify and re-bundle updated IBM MQ JAR files into affected custom Java applications.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>java</category><category>middleware</category><category>cve-2026-12666</category><category>rce</category><category>dos</category></item></channel></rss>